Back to skill

Security audit

Git Cli Paid

Security checks for vulnerabilities and agentic risk

Overview

This Git automation skill is mostly aligned with its stated purpose, but it recommends global plaintext Git credential storage and broad mutating batch operations that users should review carefully before installing.

Install only if you are comfortable with an agent running Git commands and editing files in your repositories. Avoid the documented `credential.helper store` command; use an OS-backed credential manager or SSH keys instead. Require explicit confirmation before pushes, cleanup, branch deletion, or batch operations across multiple repositories.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:258
Finding

Global Configuration Enables Plaintext Git Credential Storage

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 258
Vulnerability Type: Plaintext storage of sensitive credentials
Risk Level: Medium

Vulnerable Code:

bash
git config --global credential.helper store

Technical Analysis

The documented command configures Git's store credential helper globally. After a user authenticates to a Git remote, this helper commonly persists the supplied username and password or access token in plaintext in ~/.git-credentials.

This creates a credential-at-rest exposure because the stored secret is not protected by an operating-system credential vault or encryption. Any process or account able to read the user's credential file may recover reusable repository credentials. The --global scope also affects repositories unrelated to this Skill, exceeding the minimum privileges and configuration scope required for Git workflow automation.

The project does not itself transmit credentials to an attacker-controlled destination, and no such destination was identified. However, the insecure storage instruction can make credentials available for subsequent local theft or accidental disclosure.

Attack Path

  1. A user follows the Skill's setup instructions and runs the global Git configuration command.
  2. The user authenticates to an HTTPS Git remote with a password or personal access token.
  3. Git's credential helper writes the authentication material to the user's plaintext credential file.
  4. Local malware, another process operating with the user's privileges, an improperly authorized local account, or a backup process reads or exposes that file.
  5. An attacker extracts the stored credential and submits it to the corresponding Git hosting service.
  6. The attacker performs repository operations allowed by the credential's server-side permissions.

This path requires local read access or disclosure of the credential file; the audited Skill contains no mechanism th ...[truncated 656 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the recommendation to use credential.helper store.
  2. Recommend an operating-system-backed credential manager, such as Git Credential Manager, macOS Keychain, Windows Credential Manager, or an appropriate Linux secret service.
  3. Alternatively, recommend SSH authentication using a passphrase-protected private key and an SSH agent. Clarify that private keys must not be committed to repositories or shared.
  4. Avoid modifying global Git configuration automatically. If configuration is required, use the narrowest practical scope and obtain explicit user approval.
  5. Encourage narrowly scoped, short-lived access tokens with only the repository permissions required for the requested operation.
  6. Instruct existing users to disable the insecure helper and rotate any credentials that may have been stored:
    bash
    git config --global --unset credential.helper
    
    Users should then securely remove exposed plaintext credential records and revoke or rotate the corresponding tokens through their Git hosting provider.
  7. Require explicit confirmation before outbound pushes, batch synchronization, or destructive cleanup, especially when operating across multiple repositories.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Vague Triggers

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation/usage description is overly broad and invites use for loosely defined 'automation' and 'efficiency' scenarios without clear task boundaries or safety constraints. In a skill that also advertises exec/write capabilities, ambiguous activation criteria increase the chance the agent will perform impactful repository or system actions in contexts where the user did not intend such operations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The description explicitly states '支持中文交互' while the rest of the document is predominantly Chinese, and there is no indication that users may choose another language. This creates a natural-language policy concern because the skill appears to enforce a specific language without clear opt-in or alternatives.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill declares read/exec/write tooling and automation behavior without a prominent warning at the start that it can modify files and execute shell commands. Because the skill is positioned as a general Git assistant, users may invoke it expecting advisory help while the agent is empowered to run commands that change repositories, credentials, or local files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The examples create files such as repos.txt and demonstrate batch sync/cleanup across multiple repositories without warning about data integrity, scope, or rollback. In context, this is more dangerous because Git operations can propagate unintended changes, remove local state, or affect many repositories at once, especially when copied verbatim by an agent or user.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The 'API Key 配置' section states the skill is Markdown-instruction-based and requires no additional API key, which sets a clear expectation about external authentication needs. Later FAQ text explicitly says some features do require corresponding platform API keys and should be configured through environment variables, directly contradicting the earlier claim.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.