Back to skill

Security audit

Merge Check Paid

Security checks for vulnerabilities and agentic risk

Overview

This skill is a PR analysis helper, but it asks for command execution, file writes, and GitHub credentials while relying on an unspecified script that is not included in the package.

Review this skill before installing. Use it only if the publisher supplies the exact script or implementation, run it as an unprivileged user, give it the narrowest GitHub token or PAT scopes possible, keep webhook secrets out of reports, and direct generated files to known output paths. Avoid following the administrator-execution advice, and install optional Python dependencies in a pinned, isolated environment.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:81
Finding

Execution Instructions Reference an Unspecified and Missing Script

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 81-84
Vulnerability Type: Unverified command execution and unsafe argument handling
Risk Level: Medium

Vulnerable Snippet

The following is an English rendering of the documented commands:

bash
# Analyze all open pull requests in a repository
bash [refer to the script file in the skill directory] owner/repo --state open --limit 20

# Generate a team dashboard
bash [refer to the script file in the skill directory] owner/repo --format dashboard > pr-dashboard.html

Similar unspecified command examples appear through line 126.

Technical Analysis

The instructions direct the Agent to execute a Bash script but do not provide its filename or implementation. The audited project contains only SKILL.md, so there is no local script whose identity, integrity, argument parsing, or behavior can be reviewed.

Repository identifiers, labels, author names, and output paths are presented as command-line arguments in related examples. If an Agent attempts to infer the missing command or constructs a shell command by concatenating user-provided values, shell metacharacters could be interpreted as additional commands. Whether exploitation is possible depends on how the absent implementation or Agent handles those parameters; the provided artifact does not implement validation or safe process invocation.

Attack Path

  1. A user invokes the Skill and supplies a crafted repository identifier or another command parameter.
  2. The Agent encounters the unspecified script placeholder and guesses, substitutes, or dynamically constructs an executable command.
  3. The Agent interpolates the supplied value into a shell command without strict validation or argument separation.
  4. Shell metacharacters in the value may be interpreted as additional commands.
  5. Those commands execute with the Agent process's permissions and may inherit access to configured GitHub c ...[truncated 466 chars]
Remediation
View remediation

Remediation Suggestions

  • Include the intended script in the project and reference it using an exact, repository-relative path.
  • Review and document the script's complete behavior before instructing an Agent to execute it.
  • Invoke processes using structured argument arrays rather than concatenated shell strings.
  • Validate repository identifiers against a strict format such as owner/repository.
  • Apply allowlists and length limits to state, label, author, output-format, and path parameters.
  • Reject shell metacharacters and path traversal sequences where they are not legitimate.
  • Avoid using eval, bash -c, or equivalent dynamic shell evaluation.
  • Run the tool in a restricted environment with minimal filesystem and network permissions.
  • Document and enforce the minimum GitHub token scopes required by each operation.

T08 · Insecure Dependencies

Note
Location
SKILL.md:204
Finding

Unpinned Runtime Installation of a Third-Party Dependency

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 204
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: Low

Vulnerable Snippet

bash
pip install matplotlib

Technical Analysis

The setup guidance installs matplotlib without a pinned version, lockfile, package hash, isolated environment, or explicit trusted package index. As a result, the installed version and transitive dependency set may change between executions.

Although matplotlib is a legitimate package and there is no evidence that the document intentionally selects a malicious dependency, mutable dependency resolution reduces reproducibility and increases exposure to compromised releases, package-index redirection, or malicious transitive dependencies. Python package installation can execute build-system code during source distribution builds.

Attack Path

  1. An operator follows the dependency instructions and runs the unpinned installation command.
  2. pip resolves the latest compatible package and transitive dependencies from its configured index.
  3. A compromised index, malicious mirror, compromised release, or unsafe transitive package supplies attacker-controlled package content.
  4. Build or installation logic executes under the operator's account, or malicious code executes when the installed package is imported.
  5. The malicious code gains access to resources available to that account.

Impact Assessment

A compromised dependency could execute code with the privileges of the user running pip or the process importing the package. Accessible resources could include local project files, report data, environment variables, and credentials available to the process. System-wide impact would be possible if installation were performed with elevated privileges, but the audited installation command does not itself request elevation.

Remediation
View remediation

Remediation Suggestions

  • Pin a reviewed version of matplotlib and all transitive dependencies.
  • Store dependencies in a lockfile generated by a reproducible dependency-management tool.
  • Require package hashes, for example through a hash-locked requirements file.
  • Configure installation to use an explicitly trusted package index over HTTPS.
  • Install dependencies in a dedicated virtual environment or disposable container.
  • Prefer prebuilt, verified wheels and disable source builds where operationally practical.
  • Run dependency vulnerability and provenance checks in CI.
  • Avoid installing Python packages with administrator or root privileges.

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:370
Finding

Troubleshooting Guidance Recommends Unnecessary Administrator Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 370
Vulnerability Type: Violation of least-privilege execution
Risk Level: Medium

Vulnerable Snippet

The troubleshooting table provides the following guidance:

text
Insufficient permissions | The current user lacks read/write permission |
Check file permissions and run as administrator

Technical Analysis

The document recommends running the workflow as an administrator in response to a generic file-permission error. It does not identify a specific operation that legitimately requires elevated privileges, define the required filesystem locations, or recommend narrowly scoped permission changes.

This is particularly risky because the same Skill contains instructions to execute an unspecified script and install a third-party package. Elevating the entire Agent or shell session increases the consequences of accidental misuse, unsafe command construction, a compromised dependency, or a substituted executable.

Attack Path

  1. A command invoked through the Skill encounters a file-permission failure.
  2. The operator follows the troubleshooting advice and restarts the Agent, terminal, or command with administrator privileges.
  3. The workflow executes an unspecified script, processes untrusted parameters, or installs a dependency in the elevated context.
  4. A malicious or defective component performs privileged filesystem or system operations.
  5. The component modifies or reads resources that would have been inaccessible to the original user.

Impact Assessment

Elevated execution could permit access to protected files, system-wide configuration, other users' data, privileged credential stores, or global software installation locations. Depending on the operating system and the executed command, it could also permit system modification. The document does not itself perform privilege escalation automatically; exploitation requires an ope ...[truncated 58 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the generic recommendation to run the workflow as an administrator.
  • Identify the exact files and directories the Skill needs to read or write.
  • Use a dedicated working directory owned by the unprivileged Agent account.
  • Correct ownership or grant narrowly scoped permissions only to the required resources.
  • Abort with a clear diagnostic when an operation unexpectedly requires elevated access.
  • Separate any genuinely privileged setup step from routine Skill execution.
  • Require explicit operator confirmation and document the exact privileged command if elevation is unavoidable.
  • Ensure dependency installation and repository analysis always run as an unprivileged account.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The invocation guidance is overly broad, describing use for general data analysis, reporting, statistics, and visualization rather than narrowly scoping the skill to PR merge analysis. In agent environments, broad trigger phrases can cause the skill to activate in unrelated contexts, unnecessarily granting access to exec, read, and write capabilities and increasing the blast radius of prompt- or context-driven misuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill instructs users to copy and edit configuration files and later generate output files, but it does not clearly warn that invoking the workflow will modify local files. In an agent-driven environment, hidden write behavior can lead to unanticipated repository changes, overwriting of existing files, or unsafe persistence of generated content and secrets-adjacent configuration.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The dependency section explicitly states '无需额外API Key' and only mentions gh authentication via GITHUB_TOKEN, implying no separate API-key setup is needed. Later FAQ text states that some features do require corresponding platform API keys, which directly contradicts the earlier setup guidance and can mislead users about credential requirements.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The documentation claims that only whitelisted commands are executed, but the declared tool surface includes generic exec and example usage invokes shell commands without defining an actual allowlist or argument constraints. In an agent setting, this can mislead operators into believing command execution is constrained when it may in fact permit broader shell access, increasing the chance of unsafe execution with repository-controlled or user-controlled inputs.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.