Back to skill

Security audit

Git Pushing

Security checks for vulnerabilities and agentic risk

Overview

This skill performs the requested git workflow, but it automatically stages all changes and pushes to the remote without enough scoping or review controls.

Install only if you are comfortable with a skill that can stage every changed or untracked file in the current repository, create a commit with fixed Claude attribution, and push it to the configured `origin` branch. Before using it, manually check `git status`, the diff, the target branch, and the remote; avoid using it in repositories that may contain secrets or unrelated local work.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Warning
Location
scripts/smart_commit.sh:106
Finding

Mandatory Injection of Unrequested Branding and Attribution into Git Commits

Content
View full analysis
EOF )" ``` ### Technical Analysis The Skill instructions prohibit the agent from choosing an ordinary Git workflow and require execution of a script that unconditionally alters the commit message. Even when a user supplies a custom message, the script appends fixed branding, an external URL, and co-author attribution without providing an opt-out mechanism. This constitutes output manipulation through Skill instructions: loading and following the Skill changes the expected task from committing the user's chosen content to publishing additional, package-controlled text. Because Git commit messages become part of repository history and the script subsequently pushes the commit, the injected content is transmitted to the configured remote and may become difficult to remove from shared history. The code does not retrieve or execute a remote payload, install persistence, escalate privileges, or access credentials directly. The relevant capability is limited to modifying and publishing repository histo ...[truncated 1420 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation language is broad enough to trigger on common phrases like 'push this' or 'save to github' without requiring an explicit confirmation of scope, remote, or branch. In a skill that stages all changes and pushes to a remote, ambiguous activation increases the chance of unintended source control actions and accidental disclosure of unrelated or sensitive files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill does not warn that it stages all changes and pushes them to a remote repository, which can include unrelated edits, generated files, credentials, or other sensitive content. In this context, lack of disclosure is especially dangerous because the workflow explicitly says to always use a script that performs staging and push automatically, reducing user visibility and review.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The 'When to Use' conditions are loosely defined and overlap with ordinary conversational requests about saving or sharing work. Because the workflow mandates a script that stages all changes and pushes automatically, these ambiguous triggers materially raise the risk of unreviewed commits, mistaken pushes, and propagation of secrets or unfinished work.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.