Back to skill

Security audit

github-fetcher

Security checks for vulnerabilities and agentic risk

Overview

This skill fetches GitHub repository files for analysis, and its network access is disclosed and aligned with that purpose.

Install this if you want agents to fetch and analyze GitHub repositories with curl. Be aware that repository names, branches, and paths you ask about will be requested from GitHub, and fetched repository text should still be treated as untrusted content rather than executed code.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation criteria are broad enough to trigger on many ordinary requests about GitHub URLs or repository understanding, which can cause the skill to run in contexts the user did not explicitly intend. Because the skill then directs the agent to make outbound network requests, overbroad triggering increases the chance of unnecessary external access and unintended data handling.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

The skill explicitly instructs the agent to send data to external GitHub endpoints using curl. Even though GitHub is the intended destination, automatic outbound requests can disclose user-supplied repository targets, consume network privileges, and fetch untrusted remote content without an explicit consent or safety gate; the 'ALWAYS use curl' wording makes this more dangerous by removing discretion.

Content

Scanner excerpt · SKILL.md (reported line 13)May include surrounding context.

Standard analysis workflow

bash
# 1. List root directory
curl -s "https://api.github.com/repos/OWNER/REPO/contents/"

# 2. Get README
curl -s "https://raw.githubusercontent.com/OWNER/REPO/main/README.md"

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This instruction expands the external-fetch workflow to additional repository paths based on prior findings, which can lead to iterative remote retrieval of arbitrary repository content. In context, the skill is designed for repository analysis, so some network access is expected, but the unqualified fetch-first behavior still increases exposure to unnecessary outbound transmission and retrieval of adversarial content.

Content

Scanner excerpt · SKILL.md (reported line 19)May include surrounding context.

curl -s "https://raw.githubusercontent.com/OWNER/REPO/main/README.md"

3. Explore key subdirectories based on findings

curl -s "https://api.github.com/repos/OWNER/REPO/contents/src"

text

## Get specific file

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The description includes Chinese trigger examples alongside English instructions, but it does not state whether responses should match the user's language or offer any language preference choice. This can create an implicit language behavior without explicit user opt-in or documented locale handling.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.