Back to skill

Security audit

GitHub Address Comments

Security checks for vulnerabilities and agentic risk

Overview

The skill appears designed to help with GitHub PR comments, but it asks for broader GitHub privileges and elevated command execution than its helper code needs.

Install only if you are comfortable giving the agent access to GitHub PR discussion data and using your gh authentication. Prefer a fine-grained, least-privilege GitHub token for the target repository, avoid granting workflow scope unless a specific user-approved change requires it, and review any proposed file or repository changes before they are applied.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:10
Finding

Excessive GitHub Scopes and Blanket Elevated Network Access

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 10-12
Vulnerability Type: Excessive permissions and unnecessary privilege escalation
Risk Level: Medium

Vulnerable Code Snippet:

markdown
Guide to find the open PR for the current branch and address its comments with gh CLI. Run all `gh` commands with elevated network access.

Prereq: ensure `gh` is authenticated (for example, run `gh auth login` once), then run `gh auth status` with escalated permissions (include workflow/repo scopes) so `gh` commands succeed. If sandboxing blocks `gh auth status`, rerun it with `sandbox_permissions=require_escalated`.

Technical Analysis

The skill directs the agent to run every GitHub CLI command with elevated network access and to use credentials that include broad repo and workflow scopes. This conflicts with the principle of least privilege.

The bundled implementation only performs read operations: it obtains pull-request metadata with gh pr view and retrieves comments, reviews, and review threads through gh api graphql. The workflow scope is not required for those operations and can authorize sensitive changes to GitHub Actions workflow files. Blanket escalation of all GitHub CLI commands is also broader than the demonstrated need for narrowly scoped network access.

The script itself does not directly modify workflows or misuse the credential. The risk arises because the skill establishes an unnecessarily privileged execution and authentication context that another compromised component, malicious repository instruction, or later command could abuse.

Attack Path

  1. A user invokes the skill to inspect or address pull-request comments.
  2. The skill directs the agent to authenticate GitHub CLI with broad repo and workflow scopes.
  3. It also directs the agent to execute all gh commands with elevated network access, including retrying outside normal sandbox restrictions.
  4. A compromis ...[truncated 1052 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the instruction to include the workflow scope because the current implementation does not modify workflow files.
  2. Use a fine-grained GitHub token with read-only access to pull requests and repository metadata for comment retrieval.
  3. Separate read and write operations. Request additional authorization only after the user selects comments and a concrete repository modification is necessary.
  4. Replace the blanket instruction to elevate all gh commands with narrowly scoped network elevation for only the specific GitHub API calls that require it.
  5. Do not treat failure of gh auth status as sufficient justification to bypass sandbox restrictions automatically. Explain the required access and obtain explicit user approval before escalation.
  6. Document the minimum required GitHub permissions and validate them before execution. Reject credentials that are insufficient, but do not instruct users to grant unrelated scopes.
  7. Preserve the existing use of argument arrays without a shell in scripts/fetch_comments.py, which reduces command-injection exposure.
Vulnerability Patterns
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (3)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The documented purpose says the skill helps address PR comments, but the behavior also includes retrieving detailed PR discussion data, metadata, and exporting comments/threads as JSON without clearly disclosing that broader data collection. This mismatch reduces informed consent and can lead to overcollection of repository and review data beyond what a user reasonably expects from the description.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill invokes shell-based gh commands with elevated network access but does not declare any permissions or allowed-tools scope. That makes the skill's operational capabilities broader and less auditable than its manifest suggests, increasing the chance of unintended command execution or data access when the agent follows the instructions.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/fetch_comments.py (reported line 96)May include surrounding context.

python
def _run(cmd: list[str], stdin: str | None = None) -> str:
    p = subprocess.run(cmd, input=stdin, capture_output=True, text=True)
    if p.returncode != 0:
        raise RuntimeError(f"Command failed: {' '.join(cmd)}\n{p.stderr}")
    return p.stdout

Static analysis

No suspicious patterns detected.