T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:22- Finding
Excessive Filesystem and Command-Execution Permissions
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is presented as a GitHub PR mergeability checker, but it requests broad file and command powers and gives vague execution instructions, so it should be reviewed before use.
Install only if you are comfortable granting this skill read, write, and command-execution authority in a tightly sandboxed workspace. Use a least-privilege GitHub token, avoid exposing broad environment credentials, and require explicit approval before any command execution or file writes.
SKILL.md:22Excessive Filesystem and Command-Execution Permissions
The manifest and top-level description present the skill as a narrow GitHub PR mergeability analyzer, but the content expands it into generic data analysis, visualization, file processing, API use, and command execution. That scope drift is dangerous because it can cause an agent or user to grant broader trust and capabilities than are justified by the stated purpose, increasing the chance of unintended file access, command execution, or misuse under a misleading label.
The invocation and description are overly broad, inconsistent, and partially unrelated to PR mergeability, including generic analytics and reporting language. This weakens user consent and agent policy alignment because the skill can be invoked under a narrow expectation while actually encouraging much wider behaviors and tool use.
The description explicitly states '支持中文交互,无需复杂配置即开即用', and the document is predominantly written as Chinese-first guidance without offering a language choice. Under the language/locale policy, this is a concern unless the skill clearly offers opt-in or justifies a locale restriction.
The documentation inconsistently describes the skill as both a pure Markdown instruction skill and an executable skill. This ambiguity is dangerous because reviewers and agent runtimes may misunderstand what privileges the skill expects, leading to accidental enablement of execution features or weaker scrutiny than an executable skill warrants.
Advertising generic file read/write handling in a skill that is supposed to assess GitHub PR mergeability unnecessarily broadens the operational scope. In an agent environment, this can normalize unrelated filesystem access and make it easier to exfiltrate, overwrite, or process local files outside the user’s expected task boundary.
The skill explicitly advertises system command execution without tightly binding that capability to a minimal PR-analysis workflow. Even when described as sandboxed, normalizing arbitrary command execution in a loosely scoped skill raises the risk of command abuse, environmental probing, token exposure, or execution of attacker-influenced commands.
No suspicious patterns detected.