Back to skill

Security audit

Cuihua Code Reviewer

Security checks for vulnerabilities and agentic risk

Overview

The skill is a real local code-review tool, but it can copy detected secrets into plain report files and its examples show sharing those reports without enough safety guidance.

Review generated reports before sharing or committing them, because detected passwords or API keys may be copied into code-review-report.md. Avoid using the Slack, email, CI summary, cron, or API server examples without adding redaction, access controls, cleanup, and pinned dependencies.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
analyzer.js:74
Finding

Detected Secrets Are Persisted Verbatim in a Plaintext Report

Content
View full analysis
{ secretPatterns.forEach(pattern => { if (pattern.regex.test(line)) { this.addIssue({ file: filePath, line: index + 1, severity: 'critical', category: 'security', title: `Hardcoded ${pattern.name}`, description: 'Sensitive credentials found in code', code: line.trim(), fix: 'Move to environment variables or secure vault', impact: 'Credentials could be exposed in version control or logs' }); } }); }); ``` ```javascript md += `**Code**:\n\`\`\`\n${issue.code}\n\`\`\`\n\n`; md += `**Fix**: \n${issue.fix}\n\n`; md += `**Impact**: \n${issue.impact}\n\n`; md += `---\n\n`; return md; ``` ```javascript if (args.includes('--detailed')) { const report = reviewer.generateReport('markdown'); fs.writeFileSync('code-review-report.md', report); console.log('📄 Detailed report saved to code-review-report.md'); } ``` ### Technical Analysis When a secret-detection pattern matches, the analyzer stores the entire source line in `issue.code`. Markdown report generation then inserts that line without redaction, and detailed mode writes the resulting report to the predictable plaintext path `code-review-report.md`. Consequently, a credential that initially exists in one reviewed source file is copied into a second file. The report may be retained as a CI artifact, committed to version control, uploaded for review, included in backups, or exposed to users who can read generated reports but cannot access the original source. The fixed output name also overwrites any existing file at that path in the current working directory. The principal security concern, however, is disclosur ...[truncated 1350 chars]
Remediation
View remediation
{ const prefix = secret.slice(0, 4); return `${quote}${prefix}…REDACTED${quote}`; }); ``` 2. Prefer reporting only the secret type, file, and line number. Avoid including any portion of passwords and include only a minimal non-sensitive prefix where operationally necessary. 3. Apply redaction before data enters `this.issues`, ensuring JSON, terminal, Markdown, and future output formats are all protected. 4. Create reports with restrictive permissions, such as mode `0o600`, and allow callers to choose an explicit output path: ```javascript fs.writeFileSync(outputPath, report, { mode: 0o600, flag: 'wx' }); ``` 5. Warn before overwriting an existing report or use exclusive creation. 6. Add `code-review-report.md` and report directories to `.gitignore`. 7. Ensure CI systems do not publish unredacted reports or logs as artifacts. 8. Add tests proving that representative API keys, passwords, and tokens never appear in generated terminal, JSON, or Markdown reports. ]]>

T08 · Insecure Dependencies

Warning
Location
EXAMPLES.md:135
Finding

CI Example Executes an Unpinned Registry Package Through npx

Content
View full analysis
> $GITHUB_STEP_SUMMARY ``` ### Technical Analysis The documented CI workflow invokes `npx clawhub` without a pinned package version, lockfile, integrity digest, or immutable source revision. Depending on the local npm cache and `npx` behavior, this can download and execute the package currently resolved under the `clawhub` name. The effective executable can therefore change after the workflow has been reviewed. A compromised registry account, malicious future release, package-name takeover, or dependency-chain compromise could cause attacker-controlled lifecycle or CLI code to run inside the CI runner. The example also uses mutable major-version tags for GitHub Actions (`actions/checkout@v3` and `actions/setup-node@v3`). These are less reproducible than immutable commit SHA references, although the unpinned `npx` command is the primary finding. ### Attack Path 1. An organization copies the documented workflow into its repository. 2. An attacker compromises the registry package, its publisher account, or a transitive dependency used by the dynamically resolved `clawhub` package. 3. The attacker publishes a malicious release that satisfies unpinned resolution. 4. A pull request or scheduled CI run executes `npx clawhub install code-reviewer`. 5. `npx` downloads and runs the malicious package in the CI runner. 6. The malicious co ...[truncated 924 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (18)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
93% confidence
Finding

The pre-commit example explicitly suggests bypassing the security gate with git commit --no-verify, normalizing a simple way to skip checks that may catch critical issues. In a security-oriented skill, encouraging users to evade enforcement materially weakens the protective control and makes exploitation or accidental insecure commits more likely.

Content

Scanner excerpt · EXAMPLES.md (reported line 113)May include surrounding context.

md
if [ $? -ne 0 ]; then
  echo "❌ Code review found critical issues. Commit aborted."
  echo "💡 Fix the issues or use 'git commit --no-verify' to skip"
  exit 1
fi

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description says this skill automatically reviews code and detects issues. However, the provided code does not implement any review, scanning, reporting, or suggestion capability. Instead, it defines a test file full of intentionally bad patterns that would be input to a reviewer, not the reviewer itself. It also includes operational behaviors like shell execution, database querying, file access, network requests, and file saving, which are materially different from the declared purpose when presented as the skill’s actual code. Therefore the description does not accurately represent what this code chunk actually does.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
83% confidence
Finding

The example installs and executes clawhub via npx without pinning a specific version, which makes behavior depend on the latest published package at execution time. In CI or automated agent workflows, this creates a supply-chain risk where a malicious or compromised upstream release could be fetched and run implicitly.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The Slack example introduces outbound transmission of code review results via webhook, a capability not reflected in the skill description. Because review reports may contain sensitive code fragments, secrets, paths, or vulnerability details, undocumented external sharing increases data leakage risk and changes the trust boundary of the skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The Slack example omits any warning that review output may contain sensitive code or security findings before transmitting it to an external webhook. Users may copy this pattern directly and unintentionally leak confidential data to third-party systems.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Posting review output to a Slack webhook is not necessary for core code-review functionality and creates an unnecessary exfiltration path. In this context, reports can include proprietary code snippets, filenames, stack traces, or secrets detected during scanning, making the extra capability more dangerous than in a messaging-specific skill.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The interactive example goes beyond passive code review and shows the agent offering to modify source files automatically. That expands the effective capability of the skill from analysis to code-changing behavior, which can lead users to authorize unsafe edits or over-trust generated fixes without clear guardrails.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The API server example changes the skill from a local analyzer into a networked service that accepts untrusted input and writes it to disk. This materially expands the attack surface and operational risk beyond the stated purpose of a local code review assistant.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The API example omits a warning that submitted code is written to disk and exposed through a network service, which creates confidentiality and retention risks. Without guidance, users may deploy it with sensitive source code, unaware of persistence, local file exposure, or multi-user system concerns.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Running an HTTP API server is an unjustified capability for a code-review skill unless clearly scoped and secured, because it exposes a listening service that processes attacker-controlled input. That broadens the threat model from local analysis to remote abuse, denial of service, and mishandling of submitted code.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · EXAMPLES.md (reported line 364)May include surrounding context.

Usage

bash
curl -X POST http://localhost:3000/review \
  -H "Content-Type: application/json" \
  -d '{
    "code": "const password = \"admin123\";",

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This finding is a true security issue because the function executes a shell command using untrusted user input without validation or confirmation. In this file, the command string is built with interpolation and passed to exec, which creates a clear command injection path that can lead to arbitrary command execution on the host.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This function performs an HTTP fetch to a caller-supplied URL, but the code provides no warning, logging, or documentation that external network communication occurs. Network calls can transmit user or system data, so code files should include some form of disclosure when this behavior is present.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
44% confidence
Finding

The Privacy & Security section makes strong statements about local-only operation and no data collection. Elsewhere, the README includes external service links, which creates mild documentation ambiguity about network use, though the links are not evidence that the analyzer itself transmits code or telemetry.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

At L393, the code calls toLocaleString() with no locale selection or opt-in, which makes output language and formatting depend on the runtime environment rather than an explicit user choice. This can violate language/locale policy expectations when consistent or user-selected locale behavior is required.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The footer includes Chinese text ('翠花') as part of the generated report branding, which imposes a specific language/locale in the output without any indication of user opt-in or configurability. This is a natural-language policy concern because the file presents user-facing content in a fixed locale rather than offering a language choice or documenting a justified regional scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The function reads a local configuration file from disk, but there is no user-facing log, warning, or descriptive documentation indicating that the skill accesses local files. File access is in scope for missing-warning checks on code files when no disclosure is present.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.dynamic_code_execution, suspicious.exposed_secret_literal

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
analyzer.js:109

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
analyzer.js:143

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
test-bad-code.js:17

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
code-review-report.md:28

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
test-bad-code.js:4