Back to skill

Security audit

Code Review

Security checks for vulnerabilities and agentic risk

Overview

This code-review skill is mostly coherent, but it gives the agent authority to change and push repository code with broad staging and relies on a global agent config file outside the reviewed project.

Review carefully before installing. Use it only for repositories where you are comfortable granting GitHub CLI access, CI log access, and possible write/push authority. Do not let it run git add . or push without first inspecting the exact diff, excluding secrets and unrelated files, and giving explicit approval. Avoid relying on global ~/.claude/CLAUDE.md content as review policy unless you trust that file.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:13
Finding

Unnecessary Access to Global Agent Configuration

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 13
Vulnerability Type: Access outside the project and task boundary
Risk Level: High

Vulnerable Code

markdown
このスキルは、以下のガイドライン(`~/.claude/CLAUDE.md`)に基づいた体系的なコードレビューを提供します:

The instruction states that the Skill bases its operation on the global ~/.claude/CLAUDE.md file.

Technical Analysis

The Skill's declared function is to review source code. That task ordinarily requires read access only to the selected project, its changes, and optionally its pull-request metadata. Accessing a global Agent configuration file falls outside this scope.

A global configuration file may contain private user preferences, operating instructions, tool configuration, or rules shared across unrelated projects. It may also contain persistent instructions introduced by another project or process. Loading it expands the Skill's trust boundary and creates a route through which unrelated or attacker-controlled instructions could influence the current review.

The audited files do not contain a direct mechanism that transmits the contents of this file, so direct exfiltration is not established. The confirmed issue is unnecessary cross-project configuration access and the resulting instruction-poisoning exposure.

Attack Path

  1. An attacker or compromised process modifies ~/.claude/CLAUDE.md.
  2. A user invokes this code-review Skill on an otherwise trusted project.
  3. The Skill follows SKILL.md and loads or relies on the global configuration.
  4. Malicious persistent instructions alter review behavior, request additional access, conceal findings, or cause disclosure of contextual information.
  5. The altered behavior affects a project unrelated to the source of the malicious configuration.

Impact Assessment

Successful exploitation could influence the Agent across project boundaries and expose user-specific operating context. The accessible scope depends on the contents of the global file a ...[truncated 321 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the dependency on ~/.claude/CLAUDE.md.
  2. Store all review criteria required by the Skill inside the Skill package.
  3. If external configuration is optional, require explicit user approval before accessing a named file.
  4. Restrict external configuration to an allowlisted path and document exactly which fields are used.
  5. Treat externally loaded instructions as untrusted data and prevent them from overriding system, safety, scope, or authorization constraints.
  6. Ensure the Skill remains functional with project-scoped read access only.

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:101
Finding

Broad Repository Staging Followed by Remote Push

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 101-106
Additional Occurrence: examples.md, lines 98-103
Vulnerability Type: Unsafe source-control modification and unintended data transmission
Risk Level: High

Vulnerable Code

bash
git add .
git commit -m "fix: resolve CI failures"
git push

Technical Analysis

The command git add . stages all modified and untracked files under the applicable working-tree scope rather than limiting the commit to files deliberately changed and reviewed by the Skill. The subsequent commit and git push transmit those staged contents to the configured remote repository.

A working tree may contain unrelated user changes, generated logs, local configuration, .env files, credentials, test artifacts, or files created by another process. Broad staging therefore creates a data-flow path from arbitrary local repository content to a remote Git server.

Pushing changes is also more privileged than the Skill's core code-review function requires. Even when CI repair is requested, committing and transmitting changes should require a precise diff and explicit authorization.

Attack Path

  1. A sensitive or unrelated file exists in the repository working tree, such as an untracked .env, diagnostic log, credential export, or another developer's unfinished change.
  2. The Skill is invoked to diagnose or repair a CI failure.
  3. The prescribed git add . command stages both the intended fix and unrelated files.
  4. The Skill commits the complete staged set without a mandatory secret scan or final allowlist review.
  5. git push sends the commit to the configured remote.
  6. Anyone with access to the remote repository or its retained history may obtain the unintentionally committed data.

An attacker able to place a file in the working tree could intentionally exploit the workflow by waiting for the broad staging and push sequence.

Impact Assessment

The workflow can disclose any readable fi ...[truncated 498 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace git add . with an explicit allowlist, such as:
    bash
    git add -- src/specific-file.ts tests/specific-file.test.ts
    
  2. Run git status --short before staging and present all modified and untracked files to the user.
  3. Inspect the staged patch with:
    bash
    git diff --cached --check
    git diff --cached
    
  4. Run a secret scanner against the staged content before committing.
  5. Reject sensitive file patterns such as .env, private keys, credential exports, and generated logs unless the user explicitly authorizes them.
  6. Require explicit user confirmation for the exact staged diff before committing.
  7. Require a separate explicit confirmation before git push.
  8. Prefer creating a local patch or presenting proposed changes when the task is only a review.
  9. Use a dedicated branch with branch protection and least-privileged Git credentials when remote changes are authorized.
  10. Update examples.md so it does not reinforce the unsafe broad-staging workflow.

T08 · Insecure Dependencies

Warning
Location
reference.md:637
Finding

Execution of an Unpinned npm Registry Package Through npx

Content
View full analysis

Vulnerability Details

File Location: reference.md, line 637
Vulnerability Type: Unpinned third-party executable dependency
Risk Level: Medium

Vulnerable Code

bash
npx bundlephobia <package>

Technical Analysis

When the requested executable is unavailable locally, npx may resolve, download, and execute a package from the npm registry. The command does not specify an audited version, integrity value, lockfile, or trusted source.

This means the effective code executed during a future Skill run can differ from the code available at audit time. A compromised maintainer account, malicious package release, registry compromise, or package-resolution issue could cause arbitrary third-party code to run with the Agent's local permissions.

The command is presented as a dependency-size check rather than an explicitly malicious payload. Nevertheless, executing an unpinned registry package is unnecessary for the Skill's core review function and introduces avoidable supply-chain risk.

Attack Path

  1. A dependency-size review causes the Skill to invoke the documented npx bundlephobia command.
  2. The package is not already installed in a trusted, locked local dependency set.
  3. npx resolves a current package version from the configured npm registry.
  4. A malicious or compromised package version is downloaded.
  5. The package executable or associated lifecycle behavior runs with the Agent's user permissions.
  6. Malicious code can access files and credentials available to that account, alter the reviewed repository, or make network connections.

Impact Assessment

Exploitation could provide arbitrary code execution under the account running the Agent. The resulting scope may include access to project source, environment variables, npm credentials, Git credentials, writable user files, and network resources available to that account.

The audited project does not itself contain a malicious npm payload, and no compromise of the ...[truncated 94 chars]

Remediation
View remediation

Remediation Suggestions

  1. Do not execute registry packages dynamically during a review.
  2. Prefer a trusted read-only service or documented manual lookup for package-size information.
  3. If local execution is essential, add the tool as an audited development dependency with an exact version and lockfile integrity metadata.
  4. Invoke the locked local binary rather than allowing npx to resolve the latest registry version.
  5. Use npx --no-install where supported to prevent implicit downloads.
  6. Disable lifecycle scripts where practical and verify package provenance and integrity.
  7. Run optional dependency-analysis tools in a sandbox without access to secrets, Git credentials, or unnecessary network destinations.
  8. Document the trusted package version and establish a controlled update and re-audit process.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The activation phrases are broad enough to match routine requests like 'review this' or 'check the code', causing the skill to trigger in many ordinary contexts. Because the skill contains operational instructions involving GitHub and repository inspection, overbroad activation increases the chance of the agent invoking this workflow unexpectedly and performing actions beyond what the user intended.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill is presented as a code-review capability, but its instructions explicitly expand into making repository changes, committing, and pushing when CI fails on the user's own PR. That crosses from analysis into code modification and publication, which can trigger unintended side effects, bypass expected human review boundaries, and be abused to induce the agent to alter a codebase under the guise of 'review'.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file contains user-facing instructional content in Japanese from the outset, and the examples throughout continue in that language. Because the file does not offer a language/locale choice or explain that the skill is intentionally region-specific, it appears to impose a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guide states its content entirely in Japanese and begins with a Japanese-only description, with no indication that users may choose another language or that the skill is intentionally limited to a Japanese-specific context. Under the policy, forcing a specific language without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The when-to-use section is ambiguous and lacks boundaries for when the skill should not run, such as casual code questions, partial snippets, or contexts where no PR/repository access is intended. This ambiguity makes accidental invocation more likely and compounds the risk from the skill's broader operational behavior.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
reference.md:418