Back to skill

Security audit

Code Review

Security checks for vulnerabilities and agentic risk

Overview

This is a mostly coherent Japanese code-review skill, but it can tell the agent to modify, commit, and push repository changes without clear user approval or scoping.

Install only if you are comfortable with the skill using GitHub CLI and local Git credentials. Treat it as read-only unless you explicitly ask for fixes, and do not allow commits or pushes until you have reviewed `git status`, the staged diff, the target branch, and the remote.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:88
Finding

Unapproved Repository Modification and Remote Push

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 88–106
Vulnerability Type: Least-privilege violation through automatic repository modification and publication
Risk Level: High

Vulnerable Code

markdown
### 4. Handle CI Failures

**自分のPRでCI失敗の場合:**

1. **失敗の原因を特定**:
   - テスト失敗: どのテストがなぜ失敗したか
   - ビルドエラー: コンパイルエラー、型エラー等
   - Linter/Formatter: コーディングスタイル違反
   - セキュリティスキャン: 脆弱性検出

2. **修正を実施**:
   - エラーログを読み、根本原因を修正
   - 関連するテストケースも更新
   - ローカルで同じチェックを実行して検証

3. **再プッシュ**:
   ```bash
   git add .
   git commit -m "fix: resolve CI failures"
   git push
text

### Technical Analysis

The Skill is declared as a code-review capability, but this workflow expands its authority from inspection and reporting to modifying source files, creating commits, and publishing changes to a remote repository. It does not require explicit user authorization before these write operations.

The use of `git add .` is particularly unsafe because it stages every unignored change under the working tree rather than only the files deliberately modified and reviewed by the Agent. Unrelated local work, generated files, configuration data, or accidentally present sensitive material could therefore be incorporated into the commit.

The subsequent `git push` transmits that commit to the configured remote and changes shared repository state. The instructions do not require verification of the active branch, destination remote, protected-branch policy, staged diff, secret-scan results, or user approval. These actions exceed the minimum privileges needed to conduct a code review.

### Attack Path

1. A code-review request is made for a PR identified as belonging to the operator or Agent.
2. The CI pipeline reports a failure.
3. Following the Skill instructions, the Agent edits source code or tests.
4. The Agent runs `git add .`, staging both its intended changes and any unrelated unignored files already present in the working tree.
5. The Agent creates a commit with
...[truncated 1156 chars]
Remediation
View remediation

Remediation Suggestions

  1. Make the default workflow read-only. Produce findings and a proposed patch rather than directly modifying or publishing repository content.
  2. Require explicit user approval before each privilege-expanding phase:
    • Editing files.
    • Staging changes.
    • Creating a commit.
    • Pushing to a remote.
  3. Replace broad staging with an explicit allowlist:
    bash
    git add -- path/to/reviewed-file path/to/reviewed-test
    
  4. Require staged-content review before committing:
    bash
    git status --short
    git diff --cached
    
  5. Run an appropriate secret scanner over staged content and stop if credentials or sensitive data are detected.
  6. Verify and display the destination before pushing:
    bash
    git branch --show-current
    git remote -v
    git status --short
    
  7. Never push directly to protected or default branches. Use a dedicated branch and require the user to confirm the exact remote and branch.
  8. Prefer presenting the final push command for the user to execute manually.
  9. Document rollback procedures and preserve unrelated working-tree changes.
  10. Clearly separate “review mode” from an optional “fix mode,” with fix mode disabled unless the user expressly requests it.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (8)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation phrases are broad enough to match common user requests such as 'review this' or 'check the code,' which can cause the skill to trigger in situations the user did not specifically intend. Over-broad triggering is dangerous here because the skill includes command execution guidance and repository-interaction steps, so accidental activation raises the risk of unintended actions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest description and the document content are written to operate in Japanese, but there is no statement offering language choice or documenting a justified locale restriction. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is framed as a code-review tool, but these instructions expand its behavior into modifying source code, committing, and pushing changes when CI fails on the author's PR. That turns a review-oriented skill into one capable of making repository changes, increasing the chance of unintended or user-unapproved write actions beyond the declared purpose.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Direct instructions to git add, git commit, and git push are high-risk because they authorize persistent changes to a repository without being necessary for a code-review skill's stated function. If followed automatically, this could alter code history, publish incomplete fixes, or be abused to exfiltrate changes to remotes.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file presents its instructions and examples entirely in Japanese, beginning with the main descriptive text on L003. The policy requires flagging language or locale constraints when a skill forces a specific language without user opt-in, and this file does not indicate that Japanese is optional or region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The document content is presented entirely in Japanese beginning with the introductory sentence, with no indication that language selection is optional or that the guide is intended only for a Japanese-specific context. This creates a natural-language locale policy issue because the skill reference effectively imposes a specific language on users without opt-in.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The 'When to Use' section gives general review scenarios but does not define clear boundaries, exclusions, or whether the skill should remain read-only. This ambiguity can lead to use in contexts where CI inspection, GitHub access, or other actions are unnecessary or inappropriate.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
reference.md:418