Back to skill

Security audit

Code Reviewer

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent read-only code-review skill, but its review-scope instructions can place user-supplied Git revisions or branch names directly into shell-style commands without validation.

Install only if you are comfortable with a code-review skill that can read repository diffs and fetch GitHub/GitLab PR content. Before use, the maintainer should tighten the Git command workflow by validating commit hashes, branch names, ranges, and commit counts and by requiring structured command arguments rather than shell-style interpolation.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:84
Finding

Unvalidated Review Scope Can Reach Shell-Oriented Git Commands

Content
View full analysis
" / "cid " | Single commit | `git show ` | | "review .." | Commit range | `git diff ..` | | "review branch " | Branch vs main/master | `git diff main...` | | "review last N commits" | Recent N commits | `git diff HEAD~N..HEAD` | ``` ### Technical Analysis The Skill directs the agent to extract commit hashes, revision ranges, branch names, and commit counts from user messages and interpolate those values into Git commands. It does not require syntactic validation, reject leading options, use structured argument arrays, or define safe revision boundaries. If `RunCommand` executes the generated command through a shell, shell metacharacters in a crafted scope can introduce additional commands. Even without shell interpretation, values beginning with `-` can be interpreted as Git options and alter the intended operation. This conflicts with the Skill's stated read-only boundary because the command construction process relies on untrusted user input without enforcing that the input is only a valid Git revision. ### Attack Path 1. An attacker asks the Skill to review a commit, range, branch, or number of commits. 2. The attacker places shell syntax or Git options in the user-controlled revision value. 3. The Skill substitutes the value into the documented command template. 4. The agent invokes the resulting command through its `RunCommand` capability. 5. If the command runner uses shell evaluation, injected shell commands execute with the agent process's operatin ...[truncated 1017 chars]
Remediation
View remediation
^{commit}'` through structured arguments. - Reject revisions that fail verification. - Do not permit arbitrary Git options as revision values. 4. **Terminate option parsing where supported** - Use `--` to separate revisions or options from path arguments where appropriate. - Do not rely on `--` as a substitute for validation. 5. **Document the security requirement in `SKILL.md`** - Explicitly prohibit shell interpolation. - Require the agent to reject malformed scope values rather than attempting to repair or execute them. - Restrict `RunCommand` to an allowlist of read-only Git subcommands and approved flags. 6. **Add adversarial evaluation cases** - Test leading-option values, command separators, command substitutions, newlines, malformed ranges, and excessively large commit counts. - Assert that no command is invoked when validation fails. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (23)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 55)May include surrounding context.

md
- If the diff contains `SKILL.md`, `*.skill.md`, `.mdc`, or `.agent.md` files → also load `references/review-skill-vetter.md`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 134)May include surrounding context.

md
- If the diff contains `SKILL.md`, `*.skill.md`, `.mdc`, or `.agent.md` files → also load `references/review-skill-vetter.md`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 268)May include surrounding context.

md
- If the diff contains `SKILL.md`, `*.skill.md`, `.mdc`, or `.agent.md` files → also load `references/review-skill-vetter.md`

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/review-skill-vetter.md (reported line 62)May include surrounding context.

md
#### 1. [凭证泄露] 要求用户粘贴 Token 到聊天
📄 `SKILL.md:行号`
**规则来源**: skill-vetter
**问题**: 用户被要求将 Figma Token 粘贴到聊天,agent 自动写入 .env 文件
**风险**: Token 可能被记录在聊天历史或日志中
**建议**: 改为引导用户在本地设置环境变量,agent 仅从环境变量读取

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

文件标题明确标注为“中文说明”,整体内容也仅以中文提供,但未说明这是可选本地化版本,或是否存在其他语言版本。根据规则,技能若强制特定语言而未提供用户选择或合理限定,属于自然语言/地区策略违规。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger phrase review is extremely generic and likely to appear in ordinary conversation, commit discussions, or prompts unrelated to invoking this skill. That creates a real risk of accidental activation, causing the agent to inspect repository diffs or code context when the user did not explicitly intend to run the skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger list includes generic phrases like 'review', 'code review', and 'check my changes', which are common in normal conversation and may activate the skill in unintended contexts. Over-broad activation can cause unnecessary repository inspection or remote fetching, increasing data exposure risk and surprising users who did not intend to invoke this skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The usage examples reinforce ambiguous activation by treating very broad phrases as sufficient examples of when to use the skill. In an environment with automatic routing, this increases the chance of accidental invocation and unintended code or PR data retrieval, especially because the skill can use Read, RunCommand, and WebFetch.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The Safety section states the skill is read-only and must never modify repository code, yet later workflow text invites the user to request generated corrected code. This inconsistency weakens operator trust boundaries and may enable policy bypass in systems that grant broader use based on declared read-only semantics.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill markets itself as read-only and 'never modifies code', but its Next Steps explicitly offer to 'generate the corrected code'. Even if generation alone does not auto-write files, this creates a capability/expectation mismatch that can cause downstream agents or orchestrators to treat a supposedly non-modifying review skill as safe for restricted contexts while it still produces patch-ready code.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This JSON eval file is a manifest-type file, so vague-trigger checks apply. The trigger phrase '帮我看看代码' ('help me look at the code') is broad natural language that could overlap with ordinary conversation, and the assertion treats it as a valid activation phrase without adding narrow scope constraints or exclusions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file is entirely written as a prescriptive review template in Chinese, beginning with a Chinese title and instructions, and it does not indicate that the reviewer may choose another language. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation unless the regional constraint is explicit and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file is written entirely in Chinese and prescribes report sections and labels in Chinese, effectively forcing a specific language for skill behavior. Under the policy, locale or language constraints should either be optional for the user or clearly justified as region-specific; neither is stated here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The entire skill file is written as mandatory Chinese-language instructions, including the activation guidance and reporting requirements, without indicating that users may choose another language. This creates a language/locale policy issue because it implicitly forces a specific language without user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The title and the entire prescribed report format are in Chinese, and the template requires Chinese labels and content structure. This imposes a specific language/locale on the user-facing output with no opt-in or explanation that the skill is region-specific, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

L04 将 skill 的手动触发描述为包含“skill review”“agent review”等通用性较强的短语,但未说明上下文限制、排除条件或负例。这些表达在常见协作或审查对话中也可能自然出现,容易导致技能被意外调用。

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/review-skill-vetter.md (reported line 30)May include surrounding context.

md
- **实际权限 > 声称的能力**:SKILL.md 描述的 scope(如"只读取文件")是否与实际指令一致?(例如声称只读但包含写文件指令)
- **缺少用户同意**:文件写入/网络请求/项目扫描前是否有明确的用户同意步骤?
- **写入范围未声明**:写入操作是否限定了目标路径?是否可能写入到用户项目的敏感区域?
- **sudo/提权请求**:是否要求以管理员/sudo 权限运行?

## 4. 不安全执行

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file is entirely written as a prescriptive review guide in Chinese and gives no indication that language selection is optional or configurable. Under the policy, forcing a specific language or locale without user opt-in is a natural-language policy violation unless the constraint is explicitly justified.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/review-typescript.md (reported line 66)May include surrounding context.

md
- **`innerHTML` / `dangerouslySetInnerHTML`**:是否有充分理由?输入是否经过 DOMPurify 或其他安全转义?
- **`eval` 及其变体**:`eval`、`new Function()`、`setTimeout(string)` 在依赖用户输入时是 RCE 风险
- **`prototype` 污染**:`obj[key] = value` 中 `key` 是否来自用户输入?`__proto__`、`constructor` 等 key 是否被过滤?
- **URL 拼接注入**:`https://api.com/${userInput}` 是否可能导致 SSRF 或 Open Redirect?
- **`localStorage` / `sessionStorage` 存储敏感数据**:Token、PII 是否存储在无保护措施的前端存储中?(HttpOnly Cookie 或加密方案更安全)
- **依赖供应链**:`package.json` 中新引入的依赖是否来自可信源?是否包含已知 CVE 的版本?

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The changelog content is written in Chinese, and there is no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking audience. This can conflict with language/locale policy expectations for user-facing skill materials when no opt-in or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The note field is written as a Chinese-only organizational description, and the eval cases/assertions are also predominantly specified in Chinese. This creates a language expectation in the skill artifact without any indication that users may choose or opt into another language.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest says the skill reviews code and is read-only, but this eval file explicitly expects it to parse a GitHub PR URL and fetch a .diff over the network. While read-only, network access is a broader behavior than the description states, so the documented intent and tested behavior are not perfectly aligned.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

标题及全文均以中文固定表述该技能的审查维度,且未说明是否支持其他语言或由用户选择输出语言。若组织要求避免未经用户选择而强制特定语言,这种默认单一语言描述可能构成自然语言策略违规。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.