T09 · Insecure Skill Coding Practices
- Location
SKILL.md:62- Finding
Untrusted Webhook Data Is Embedded into Downstream Control Messages
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is coherent with its GitHub-to-Pilot bridge purpose, but its example exposes a public event relay and uses webhook data to trigger downstream agents without documenting basic authentication or validation controls.
Review this skill carefully before installing. Use it only with a private or authenticated relay, GitHub webhook signature verification, repository and branch allowlists, strict event validation, replay/rate limiting, and least-privilege downstream agents. Do not run the public relay example as-is for production automation.
SKILL.md:62Untrusted Webhook Data Is Embedded into Downstream Control Messages
SKILL.md:53Public Daemon and Relay Exposure Lacks Documented Access Controls
The skill instructs users to run a public daemon and an externally exposed webhook relay, then consume and act on inbound GitHub event data without documenting authentication, signature verification, sender validation, or replay protection. In this context, untrusted network input is directly used to trigger downstream agent actions such as builds and code review messages, which can let an attacker spoof events or induce unauthorized workflow execution.
The manifest explicitly scopes the skill to bridging webhook events and says not to use it for direct GitHub API access. However, the dependency list states that gh CLI is required, which implies GitHub API tooling outside the webhook-bridge purpose and does not match the rest of the documented workflow, which never uses gh.
No suspicious patterns detected.