Back to skill

Security audit

github-autosetup

Security checks for vulnerabilities and agentic risk

Overview

This skill is for GitHub automation, but it installs persistent automation that can commit and push all repository changes without fresh review.

Install only for repositories where you truly want unattended publishing to GitHub. Review and edit the installer before running it, avoid enrolling repositories that may contain secrets or work in progress, confirm repository visibility, add strong .gitignore and secret-scanning safeguards, and know how to remove the post-commit hooks and Windows scheduled task.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T06 · System Persistence

Error
Location
scripts/install-autopush.sh:74
Finding

Recurring Cross-Session Execution Through Windows Scheduled Tasks

Content
View full analysis
/dev/null || echo "C:\\Program Files\\Git\\bin\\bash.exe")" SCRIPT_WIN="$(cygpath -w "$AUTOPUSH" 2>/dev/null || echo "$AUTOPUSH")" schtasks //create //tn "$TASK" //tr "\"$BASH_WIN\" \"$SCRIPT_WIN\"" //sc MINUTE //mo "$MIN" //f >/dev/null 2>&1 if [ $? -eq 0 ]; then echo "task registered: $TASK (every ${MIN}min)" else echo "task FAILED (schtasks) - run manually with admin if needed" fi echo "done." ``` ### Technical Analysis The installer registers the generated `autopush.sh` as a Windows scheduled task that runs every configured number of minutes, with a default interval of 30 minutes. The `/f` option forcibly replaces an existing task with the same name. This behavior is persistent across Agent sessions and potentially across system restarts. Although scheduled synchronization is disclosed in `README.md` and `SKILL.md`, it is broader than the minimum behavior required for “push on commit,” because the installed Git `post-commit` hooks already provide event-driven pushing. The generated script does more than retry existing commits: it inspects each configured repository, stages changes, creates commits, and pushes them. Consequently, this persistent task continuously performs repository-changing operations without renewed user approval. ### Attack Path 1. The user or Agent runs `install-autopush.sh`. 2. The installer creates an executable `autopush.sh` in the selected output directory. 3. The installer registers that script under the user-controlled task name using `schtasks`. 4. Windows launches Bash and the generated script at every configured interval. 5. The script repeatedly processes and pushes repository contents after the original Skill executi ...[truncated 739 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/install-autopush.sh:57
Finding

Automatic Staging, Commitment, and Upload of All Repository Changes

Content
View full analysis
/dev/null' echo ' if [ -n "$(git status --porcelain)" ]; then' echo ' git commit -m "chore: autosync $(date "+%F %H:%M")" -q 2>/dev/null' echo ' git push origin HEAD -q 2>/dev/null && log "pushed: $r" || log "push FAILED: $r"' echo ' else' echo ' git push origin HEAD -q 2>/dev/null && log "synced(clean): $r"' echo ' fi )' echo 'done' echo 'log "--- done ---"' ``` ### Technical Analysis The generated synchronization script executes `git add -A`, which stages all unignored modifications, deletions, and untracked files in each configured repository. If any staged change exists, the script creates a commit and pushes it without displaying the staged diff or requesting user approval. This is substantially more dangerous than merely pushing existing user-created commits. The Skill’s stated sensitive-information procedure does not technically prevent secret files from being staged. Protection depends entirely on each target repository having complete and correct ignore rules. Files such as `.env`, local credential exports, application configuration, debugging captures, private notes, and generated data can therefore be committed and uploaded if they are not ignored. The audited project’s own `.gitignore` only contains: ```gitignore .DS_Store Thumbs.db *.log ``` It does not demonstrate protection for common secret-bearing files. Suppression of command output with `2>/dev/null` also reduces the user’s ability to identify errors or unintended behavior. ### Attack Path 1. A repository is enrolled in automatic synchronization. 2. A user, application, or Agent creates or modifies a sensitive file inside that repository. 3. The file is not covered by the repository’s ignore rul ...[truncated 861 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/install-autopush.sh:48
Finding

Shell Command Injection Through Unescaped Paths in Generated Persistent Script

Content
View full analysis
> "$LOG"; }' echo 'ssh-add -l >/dev/null 2>&1 || log "WARN: ssh-agent has no key; run: ssh-add ~/.ssh/id_ed25519_gh"' echo 'REPOS=(' for r in "${REPOS[@]}"; do printf ' "%s"\n' "$r"; done echo ')' ``` ### Technical Analysis The installer generates executable Bash source by embedding `LOG` and repository path values inside double-quoted shell syntax. These values are not escaped for use as Bash source code. A path containing a double quote, command substitution, backticks, a newline, or other shell metacharacters can terminate the intended quoted value and insert additional shell syntax. Shell expansion then occurs when the generated `autopush.sh` is executed, rather than when the value is originally received. This issue is especially serious because the generated file is registered as a scheduled task. Successful injection therefore becomes recurring command execution rather than a one-time installer failure. ### Attack Path 1. An attacker influences a repository path or output directory passed to `install-autopush.sh`. 2. The supplied path contains characters that are valid or accepted in the surrounding environment but have special meaning when embedded in Bash source. 3. The installer writes the value directly into the `LOG` assignment or `REPOS` array without source-level escaping. 4. The generated `autopush.sh` contains attacker-controlled shell syntax. 5. The scheduled task launches the generated script. 6. Bash parses and executes the injected command. 7. The command runs again on subsequent scheduled invocations while the task remains in ...[truncated 677 chars]
Remediation
View remediation

T06 · System Persistence

Warning
Location
SKILL.md:69
Finding

Persistent Automatic Startup Configuration for the SSH Agent Service

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (19)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill claims a controlled, security-conscious GitHub setup flow, but the documented behavior also installs post-commit hooks and a scheduled task that can automatically stage, commit, and push repository contents. That mismatch is dangerous because users may consent to setup/authentication help without realizing they are enabling persistent automated publication of local changes, increasing the chance of accidental source or secret exfiltration.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

The scheduled auto-push workflow depends on a loaded SSH key and periodically retries pushing changes, creating a persistent mechanism that can publish repository contents whenever the key is available. In a skill designed for broad Git setup requests, this persistence increases the blast radius of mistakes: sensitive files committed locally may be pushed automatically without a fresh review step.

Content

Scanner excerpt · SKILL.md (reported line 106)May include surrounding context.

md
2. 生成 `autopush.sh`(仓库清单内嵌 + ssh-add 告警 + 日志)。
3. 注册计划任务(默认每 30 分钟):`schtasks //create //tn AutoSync //tr "\"<git-bash>\" \"<autopush.sh>\"" //sc MINUTE //mo 30 //f`。

**验证(必做)**:任一仓库提交临时文件 → `git ls-remote origin main` 与本地 HEAD 一致 → 清理。重启后提醒用户 `ssh-add ~/.ssh/id_ed25519_gh`(agent 重启清空)。

## 5. 收尾核查(安全自检)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script generates a scheduled background task that repeatedly stages, commits, and pushes repository contents without interactive review. In the context of a GitHub auto-setup skill, this is especially dangerous because it creates continuous exfiltration of local changes to a remote service and may include secrets, private files, or incomplete work.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 64)May include surrounding context.

md
echo '# autopush.sh - auto commit + push (generated by install-autopush.sh; no credentials)'
  echo "LOG=\"$LOG\""
  echo 'log(){ echo "[$(date "+%F %T")] $*" >> "$LOG"; }'
  echo 'ssh-add -l >/dev/null 2>&1 || log "WARN: ssh-agent has no key; run: ssh-add ~/.ssh/id_ed25519_gh"'
  echo 'REPOS=('
  for r in "${REPOS[@]}"; do printf '  "%s"\n' "$r"; done
  echo ')'

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 65)May include surrounding context.

md
echo '# autopush.sh - auto commit + push (generated by install-autopush.sh; no credentials)'
  echo "LOG=\"$LOG\""
  echo 'log(){ echo "[$(date "+%F %T")] $*" >> "$LOG"; }'
  echo 'ssh-add -l >/dev/null 2>&1 || log "WARN: ssh-agent has no key; run: ssh-add ~/.ssh/id_ed25519_gh"'
  echo 'REPOS=('
  for r in "${REPOS[@]}"; do printf '  "%s"\n' "$r"; done
  echo ')'

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 68)May include surrounding context.

md
echo '# autopush.sh - auto commit + push (generated by install-autopush.sh; no credentials)'
  echo "LOG=\"$LOG\""
  echo 'log(){ echo "[$(date "+%F %T")] $*" >> "$LOG"; }'
  echo 'ssh-add -l >/dev/null 2>&1 || log "WARN: ssh-agent has no key; run: ssh-add ~/.ssh/id_ed25519_gh"'
  echo 'REPOS=('
  for r in "${REPOS[@]}"; do printf '  "%s"\n' "$r"; done
  echo ')'

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 74)May include surrounding context.

md
echo '# autopush.sh - auto commit + push (generated by install-autopush.sh; no credentials)'
  echo "LOG=\"$LOG\""
  echo 'log(){ echo "[$(date "+%F %T")] $*" >> "$LOG"; }'
  echo 'ssh-add -l >/dev/null 2>&1 || log "WARN: ssh-agent has no key; run: ssh-add ~/.ssh/id_ed25519_gh"'
  echo 'REPOS=('
  for r in "${REPOS[@]}"; do printf '  "%s"\n' "$r"; done
  echo ')'

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/install-autopush.sh (reported line 60)May include surrounding context.

sh
echo '# autopush.sh - auto commit + push (generated by install-autopush.sh; no credentials)'
  echo "LOG=\"$LOG\""
  echo 'log(){ echo "[$(date "+%F %T")] $*" >> "$LOG"; }'
  echo 'ssh-add -l >/dev/null 2>&1 || log "WARN: ssh-agent has no key; run: ssh-add ~/.ssh/id_ed25519_gh"'
  echo 'REPOS=('
  for r in "${REPOS[@]}"; do printf '  "%s"\n' "$r"; done
  echo ')'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README repeatedly promotes '提交即自动推送' and scheduled fallback syncing, but it does not provide a prominent warning that after setup the skill will continue transmitting repository contents to a remote service automatically. In a skill that configures GitHub connectivity and background automation, missing this disclosure can cause users to unintentionally exfiltrate code, secrets, or private work product after future commits.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad enough to match routine Git help requests such as configuring Git or pushing a repository, which could invoke a high-impact automation skill unexpectedly. In this context, unintended activation matters because the skill can alter repository state, install hooks, and register scheduled tasks rather than just provide advice.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

md
| SSH 私钥 | **交互式 `ssh-keygen`(必须设口令)**,用户在自己 Git Bash 输入;解锁态驻 ssh-agent 内存 | `-N ""` 空口令;口令打进命令行参数 |
| 口令/密码 | 只出现在用户终端的交互提示中 | 发聊天里 |
| 站点 cookie(B站/贴吧) | 导出 JSON → 写**仓库外临时文件** → 转换后写入**已 gitignore 的 config** → 删临时文件;验证输出**掩码** | 把 cookie 原文粘贴进对话/提交 |
| 敏感文件落点 | 核查权限(`icacls`/`chmod 700`);报告落点(keyring vs 文件) | 不核查直接收工 |

**操作模式**:agent 打印"**终端复制块**"(用户在自己 Git Bash 执行)或直接用自身 bash 工具执行;agent 只**验证结果**(`gh auth status` / `ssh-add -l` / `git ls-remote`),全程看不见秘密。验证输出一律掩码(`sed 's/Token: .*/Token: ***/'`)。

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Installing a post-commit hook that automatically pushes to origin changes repository behavior in a persistent and non-obvious way. Users may believe a commit remains local for review, but this hook immediately transmits it, increasing the chance of accidental publication of sensitive code or data.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The generated script does more than synchronize existing commits: it stages all changes, creates new commits automatically, and pushes them on a timer. This can silently capture and transmit unintended files, secrets, or work-in-progress without per-action user review, which is a real integrity and data-exfiltration risk in a Git/GitHub automation skill.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script’s header claims it does not touch sensitive information, but it reads and prints locally configured Git identity, SSH public-key filenames, ssh-agent status, and filtered GitHub auth status. Even if full secrets are not emitted, this still exposes authentication and identity metadata that can leak account presence, usernames/emails, and token type to logs, transcripts, or an observing operator.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The command prints git config user.name and git config user.email directly with no warning or confirmation. In an agent-driven skill, that output may be captured in chat history, telemetry, or shared logs, disclosing personal identity information unrelated to the minimum needed for setup.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

gh auth status is queried and filtered for login/account/token-related lines, which can reveal active account information and token class. Although the sed commands attempt partial sanitization, they do not eliminate disclosure risk and may still expose sensitive auth state to logs or an untrusted viewer.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The usage instruction tells the user to say a Chinese trigger phrase to the agent, and the README is written as if that is the expected interaction mode. There is no indication that other languages are accepted or that the Chinese phrasing is merely an example, which may conflict with language-choice policy expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The manifest description and the entire SKILL.md are written as Chinese-only operating instructions, but there is no statement that the skill is region-specific or that the user can opt into another language. That creates a natural-language locale constraint without user choice, which matches the language/locale policy violation category.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The generated script header says 'no credentials', but the very next line checks for SSH agent keys via 'ssh-add -l' and the script performs authenticated pushes. While it may avoid storing credentials in plaintext, the comment overstates the absence of credential use and can mislead about the script's operational dependence on loaded secrets.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.