Back to skill

Security audit

file-change-tracker

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local file-change safety helper, but it automatically mutates Git repositories and can persist file contents in commits without a separate user confirmation step.

Install only if you want an agent to create local Git recovery commits around file edits. Review target paths carefully, avoid broad generated or secret-containing directories, and be aware that it may initialize Git, set local Git identity, bypass commit hooks, and leave durable local history and .git/.guarded-edit session records.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (15)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill is presented as a safety gate for file changes, but it also performs additional state-changing operations: initializing a git repository, configuring identity, creating commits, and writing session state under .git. That mismatch can surprise users and downstream agents, causing unintended persistence, history changes, or disclosure of modified content into local commits beyond what the description implies.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 67)May include surrounding context.

md
File Change Tracker uses a dedicated gitignore-style exclusion file instead of embedding default patterns in `SKILL.md`.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 76)May include surrounding context.

md
File Change Tracker uses a dedicated gitignore-style exclusion file instead of embedding default patterns in `SKILL.md`.

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · SKILL.md (reported line 101)May include surrounding context.

bash
{baseDir}/scripts/helper.sh pre "fix login validation" -- src/auth/login.ts src/auth/schema.ts
{baseDir}/scripts/helper.sh pre "create news script and docs" -- scripts/news_hotspot.py scripts/README.md
{baseDir}/scripts/helper.sh pre "update skill metadata" -- SKILL.md README.md README.user.md
{baseDir}/scripts/helper.sh pre "regenerate parser output" -- src/parser generated/

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script is presented as a file-change tracker, but it performs repository-mutating operations such as git init and git config changes inside helper functions used by normal flows. In an agent skill context, this exceeds passive tracking and can silently alter repository state and user configuration expectations, making unintended history and repo mutations likely.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The PRE/POST workflow creates commits for the selected paths, which directly modifies project history rather than merely recording metadata. In a mandatory pre-edit skill, this is dangerous because routine use can create unsolicited commits, interfere with team workflows, and leave durable history changes that the user did not explicitly request.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The use of git commit --allow-empty --no-verify bypasses client-side hooks and permits history mutation even when there is no actual content change. In this skill, that means a mandatory tracking step can silently suppress repository guardrails and inject synthetic commits, undermining policy enforcement and audit expectations.

Content

Scanner excerpt · scripts/helper.sh (reported line 566)May include surrounding context.

sh
stage_paths
    if ! scoped_staged_diff_exists; then
      unstage_paths_best_effort
      git commit --allow-empty --no-verify -m "guard(init): $SESSION_REASON" >/dev/null
    else
      create_scoped_commit "guard(init): $SESSION_REASON"
    fi

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

This second git commit --allow-empty --no-verify path has the same security impact: it can create commits while bypassing pre-commit and commit-msg hooks that may enforce secrets scanning, policy checks, or workflow controls. Because it runs automatically in a helper skill, users may not realize those protections were skipped.

Content

Scanner excerpt · scripts/helper.sh (reported line 571)May include surrounding context.

sh
create_scoped_commit "guard(init): $SESSION_REASON"
    fi
  else
    git commit --allow-empty --no-verify -m "guard(init): $SESSION_REASON" >/dev/null
  fi

  full_head="$(current_head_full)"

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The README's user-facing instructions and usage guidance are presented only in Chinese, which imposes a specific language on users without any opt-in or alternative. The policy allows locale constraints only when they are optional or clearly justified as region-specific, neither of which is stated here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The reporting template is written entirely in Chinese and is presented as the required output format. This imposes a specific language on users without opt-in or an alternative, which violates the language/locale policy criteria.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Automatically initializing a repository and setting git identity changes the user's workspace state in a persistent way, even when they may only expect a protective wrapper. Without a prominent warning or opt-in, this can create unexpected repos, alter tooling behavior, and leave audit artifacts that the user did not intend.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly allows non-ignored sensitive files within target paths to be included in snapshots, which can persist secrets or private artifacts in commit history and reflog. In a safety-oriented skill, failing to foreground this privacy risk is dangerous because users may treat the snapshot mechanism as harmless bookkeeping.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

need_git_repo automatically runs git init when the current directory is not already a repository. In an agent environment, that can unexpectedly convert arbitrary directories into git repositories, change downstream tool behavior, and create hidden state under .git without user awareness.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script automatically writes user.name and user.email to the repository config if missing. Although local in scope, this changes repository configuration without consent and can cause misleading commit attribution or violate project policy in repos where identity should be explicitly managed.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The report path prints multiple user-facing status messages in Chinese, such as "最近...次记录" and "文件变更保护状态:", with no option to choose language or detect user preference. This creates a natural-language locale policy issue because the skill imposes a specific language on all users rather than offering opt-in or configurability.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.