Security checks for vulnerabilities and agentic risk
Overview
This Git automation skill is mostly aligned with its stated purpose, but it recommends global plaintext Git credential storage and broad mutating batch operations that users should review carefully before installing.
Install only if you are comfortable with an agent running Git commands and editing files in your repositories. Avoid the documented `credential.helper store` command; use an OS-backed credential manager or SSH keys instead. Require explicit confirmation before pushes, cleanup, branch deletion, or batch operations across multiple repositories.
Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)
T09 · Insecure Skill Coding Practices
Warning
Location
SKILL.md:258
Finding
Global Configuration Enables Plaintext Git Credential Storage
Content
View full analysis
Vulnerability Details
File Location: SKILL.md, line 258 Vulnerability Type: Plaintext storage of sensitive credentials Risk Level: Medium
Vulnerable Code:
bash
git config --global credential.helper store
Technical Analysis
The documented command configures Git's store credential helper globally. After a user authenticates to a Git remote, this helper commonly persists the supplied username and password or access token in plaintext in ~/.git-credentials.
This creates a credential-at-rest exposure because the stored secret is not protected by an operating-system credential vault or encryption. Any process or account able to read the user's credential file may recover reusable repository credentials. The --global scope also affects repositories unrelated to this Skill, exceeding the minimum privileges and configuration scope required for Git workflow automation.
The project does not itself transmit credentials to an attacker-controlled destination, and no such destination was identified. However, the insecure storage instruction can make credentials available for subsequent local theft or accidental disclosure.
Attack Path
A user follows the Skill's setup instructions and runs the global Git configuration command.
The user authenticates to an HTTPS Git remote with a password or personal access token.
Git's credential helper writes the authentication material to the user's plaintext credential file.
Local malware, another process operating with the user's privileges, an improperly authorized local account, or a backup process reads or exposes that file.
An attacker extracts the stored credential and submits it to the corresponding Git hosting service.
The attacker performs repository operations allowed by the credential's server-side permissions.
This path requires local read access or disclosure of the credential file; the audited Skill contains no mechanism th
...[truncated 656 chars]
Remediation
View remediation
Remediation Suggestions
Remove the recommendation to use credential.helper store.
Recommend an operating-system-backed credential manager, such as Git Credential Manager, macOS Keychain, Windows Credential Manager, or an appropriate Linux secret service.
Alternatively, recommend SSH authentication using a passphrase-protected private key and an SSH agent. Clarify that private keys must not be committed to repositories or shared.
Avoid modifying global Git configuration automatically. If configuration is required, use the narrowest practical scope and obtain explicit user approval.
Encourage narrowly scoped, short-lived access tokens with only the repository permissions required for the requested operation.
Instruct existing users to disable the insecure helper and rotate any credentials that may have been stored:
bash
git config --global --unset credential.helper
Users should then securely remove exposed plaintext credential records and revoke or rotate the corresponding tokens through their Git hosting provider.
Require explicit confirmation before outbound pushes, batch synchronization, or destructive cleanup, especially when operating across multiple repositories.
The activation/usage description is overly broad and invites use for loosely defined 'automation' and 'efficiency' scenarios without clear task boundaries or safety constraints. In a skill that also advertises exec/write capabilities, ambiguous activation criteria increase the chance the agent will perform impactful repository or system actions in contexts where the user did not intend such operations.
Content
No source excerpt is available for this finding.
Natural-Language Policy Violations
Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding
The description explicitly states '支持中文交互' while the rest of the document is predominantly Chinese, and there is no indication that users may choose another language. This creates a natural-language policy concern because the skill appears to enforce a specific language without clear opt-in or alternatives.
Content
No source excerpt is available for this finding.
Missing User Warnings
Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding
The skill declares read/exec/write tooling and automation behavior without a prominent warning at the start that it can modify files and execute shell commands. Because the skill is positioned as a general Git assistant, users may invoke it expecting advisory help while the agent is empowered to run commands that change repositories, credentials, or local files.
Content
No source excerpt is available for this finding.
Missing User Warnings
Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding
The examples create files such as repos.txt and demonstrate batch sync/cleanup across multiple repositories without warning about data integrity, scope, or rollback. In context, this is more dangerous because Git operations can propagate unintended changes, remove local state, or affect many repositories at once, especially when copied verbatim by an agent or user.
Content
No source excerpt is available for this finding.
Intent-Code Divergence
Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding
The 'API Key 配置' section states the skill is Markdown-instruction-based and requires no additional API key, which sets a clear expectation about external authentication needs. Later FAQ text explicitly says some features do require corresponding platform API keys and should be configured through environment variables, directly contradicting the earlier claim.