Back to skill

Security audit

code-review

Security checks for vulnerabilities and agentic risk

Overview

This code-review skill is mostly coherent, but it gives the agent broad side-effecting authority such as installing untrusted dependencies, creating SSH keys, deleting local repo changes, and pushing commits without clear per-action approval.

Install only if you are comfortable with a code-review agent that can run package managers, modify review output folders, create or use SSH authentication, and push commits. Prefer read-only credentials, disposable clones or containers, no automatic dependency scripts, no curl-to-shell installers, and explicit confirmation before any git reset, clean, commit, push, or SSH-key creation.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Findings (6)

T03 · Remote Payload Retrieval and Execution

Error
Location
references/frontend_dependency_installation/node_environment.md:55
Finding

Unverified Remote Script Is Piped Directly into a Shell

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
references/python_dependency_installation/project_dependencies.md:24
Finding

Audited Repositories Can Execute Code Through Dependency Installation Hooks

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/repository_access.md:80
Finding

Repository Synchronization Permanently Deletes Local Work

Content
View full analysis
/repos// git reset --hard HEAD git clean -fd git pull origin main ``` ### Technical Analysis The synchronization procedure unconditionally discards tracked working-tree changes and deletes untracked files and directories. Neither operation is necessary to determine repository status or perform a code review. `git reset --hard HEAD` destroys uncommitted modifications to tracked files. `git clean -fd` permanently deletes untracked files and directories, including local configuration, generated artifacts, notes, or work not represented in Git. The procedure does not first check whether the working tree is dirty, create a backup, use a disposable worktree, or request user approval. ### Attack Path 1. The Skill calculates a repository path that already contains a checkout. 2. The checkout contains uncommitted tracked changes or untracked files. 3. The Skill treats the checkout as a cached remote workspace and begins its update procedure. 4. `git reset --hard HEAD` discards tracked modifications. 5. `git clean -fd` deletes untracked files and directories. 6. The deleted work cannot generally be recovered through ordinary Git history. ### Impact Assessment The operation can cause permanent data loss within the selected repository. It does not directly grant an attacker additional system privileges, but it can destroy user work and remove evidence or local safeguards. The affected scope includes all tracked modifications and untracked non-ignored content under the repository path. ]]>
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
references/report_delivery.md:12
Finding

Code Review Workflow Automatically Modifies and Pushes Remote Repositories

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
references/repository_access.md:11
Finding

Skill Automatically Creates a Persistent Passphrase-Free SSH Identity

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
references/installation.md:213
Finding

Mutable Unsigned Skill Archive Can Replace Agent Instructions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (70)

External Script Fetching

High
Category
Supply Chain
Confidence
97% confidence
Finding

curl https://get.volta.sh | bash fetches a remote script and immediately executes it, which is a classic supply-chain hazard. If the remote endpoint, TLS trust chain, network path, or hosting account is compromised, the reviewer environment can be fully compromised with arbitrary code execution.

Content

Scanner excerpt · references/frontend_dependency_installation/node_environment.md (reported line 56)May include surrounding context.

  • Unix/Linux/macOS:
    bash
    curl https://get.volta.sh | bash
    
  • Windows / PowerShell:
    powershell

Chaining Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

The | bash chaining pattern removes any inspection boundary between download and execution, turning a documentation step into direct arbitrary code execution. In the context of an automated code-review skill that may operate on remote infrastructure, this is especially dangerous because it can convert a routine setup step into full environment takeover.

Content

Scanner excerpt · references/frontend_dependency_installation/node_environment.md (reported line 56)May include surrounding context.

  • Unix/Linux/macOS:
    bash
    curl https://get.volta.sh | bash
    
  • Windows / PowerShell:
    powershell

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The document expands a code-review skill into repository mutation by automatically editing .gitignore and then committing and pushing that change upstream. For a review-only capability, this is dangerous because it authorizes write actions to a remote repository that can alter project history, trigger CI/CD, and make persistent changes unrelated to analysis.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

Embedding remote git commit/git push instructions in a code-review skill gives the skill write-back capability that is not necessary for its stated purpose. In the context of an automated agent, this creates a path for unauthorized repository changes, accidental policy violations, or abuse of available Git credentials.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/installation.md (reported line 163)May include surrounding context.

mkdir -p download_skills curl -L -o download_skills/code-review.zip "https://clawhub.ai/api/skills/download?slug=code-review&ownerHandle=tinycen" unzip download_skills/code-review.zip -d download_skills/code-review rm download_skills/code-review.zip

text

2. **移动到对应技能目录**:

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/installation.md (reported line 235)May include surrounding context.

mkdir -p download_skills curl -L -o download_skills/code-review.zip "https://clawhub.ai/api/skills/download?slug=code-review&ownerHandle=tinycen" unzip download_skills/code-review.zip -d download_skills/code-review rm download_skills/code-review.zip

text

2. **移动到对应技能目录**:

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill is described as a code-review tool, but this document authorizes mutating repository state by editing .gitignore, committing, and pushing to the remote. That exceeds a read-only review function and can cause unauthorized writes to user repositories, especially if triggered automatically in remote review flows.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Automatically executing git push grants the skill code-hosting write capability that is not necessary for code-quality analysis. If misused or triggered unexpectedly, it can alter remote repositories, create audit noise, and potentially introduce policy-violating changes under the user's identity or automation credentials.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill directs the agent to automatically commit and push generated artifacts to a remote repository, including retry logic, without a clear user-facing confirmation immediately before the remote write. This is a high-risk action because it can publish sensitive review content, trigger CI/CD workflows, mutate audit history, and exfiltrate repository-derived data to external infrastructure.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/repository_access.md (reported line 14)May include surrounding context.

md
首次从 GitHub 拉取/推送代码前,必须执行以下检查流程,确保 SSH 认证可用:

1. **检查本地是否存在 SSH 密钥**
   - 检查默认密钥路径:`~/.ssh/id_ed25519.pub` 或 `~/.ssh/id_rsa.pub`
   - 若存在:进入步骤 2
   - 若不存在:进入步骤 3(自动生成)

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/repository_access.md (reported line 28)May include surrounding context.

md
首次从 GitHub 拉取/推送代码前,必须执行以下检查流程,确保 SSH 认证可用:

1. **检查本地是否存在 SSH 密钥**
   - 检查默认密钥路径:`~/.ssh/id_ed25519.pub` 或 `~/.ssh/id_rsa.pub`
   - 若存在:进入步骤 2
   - 若不存在:进入步骤 3(自动生成)

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/repository_access.md (reported line 36)May include surrounding context.

md
首次从 GitHub 拉取/推送代码前,必须执行以下检查流程,确保 SSH 认证可用:

1. **检查本地是否存在 SSH 密钥**
   - 检查默认密钥路径:`~/.ssh/id_ed25519.pub` 或 `~/.ssh/id_rsa.pub`
   - 若存在:进入步骤 2
   - 若不存在:进入步骤 3(自动生成)

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/repository_access.md (reported line 14)May include surrounding context.

md
首次从 GitHub 拉取/推送代码前,必须执行以下检查流程,确保 SSH 认证可用:

1. **检查本地是否存在 SSH 密钥**
   - 检查默认密钥路径:`~/.ssh/id_ed25519.pub` 或 `~/.ssh/id_rsa.pub`
   - 若存在:进入步骤 2
   - 若不存在:进入步骤 3(自动生成)

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/repository_access.md (reported line 36)May include surrounding context.

md
首次从 GitHub 拉取/推送代码前,必须执行以下检查流程,确保 SSH 认证可用:

1. **检查本地是否存在 SSH 密钥**
   - 检查默认密钥路径:`~/.ssh/id_ed25519.pub` 或 `~/.ssh/id_rsa.pub`
   - 若存在:进入步骤 2
   - 若不存在:进入步骤 3(自动生成)

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Automatically creating an SSH keypair on the host modifies authentication state and establishes a durable credential without strong necessity for code review. Even though the private key is not explicitly exfiltrated, generating new credentials from within the skill creates persistence and broadens the trust boundary of the tool.

Content

Scanner excerpt · references/repository_access.md (reported line 26)May include surrounding context.

md
3. **自动生成 SSH 密钥(无密钥时)**
   - 生成 ed25519 密钥对:
     ```bash
     ssh-keygen -t ed25519 -C "code-review@automation" -f ~/.ssh/id_ed25519 -N ""
     ```
   - 读取公钥内容:`cat ~/.ssh/id_ed25519.pub`
   - **将公钥内容发送给用户**,并提示:

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
96% confidence
Finding

git reset --hard is a destructive command that discards local tracked changes with no recovery path in normal workflows. In a code-review skill context, embedding this as a default update step creates significant risk of accidental loss and can be abused if the agent is induced to run it in an unintended repository.

Content

Scanner excerpt · references/repository_access.md (reported line 84)May include surrounding context.

md
当本地已存在目标仓库时:

1. 进入该仓库目录
2. 执行 `git reset --hard HEAD` 重置本地修改
3. 执行 `git clean -fd` 清理未跟踪文件
4. 执行 `git pull origin main` 拉取最新代码

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
96% confidence
Finding

The command block operationalizes a destructive reset as copy-pastable guidance, making unsafe execution more likely. Because the skill is for code review rather than repo administration, normalizing this parameter use violates least privilege and increases the blast radius of mistakes.

Content

Scanner excerpt · references/repository_access.md (reported line 92)May include surrounding context.

bash
cd <workspace>/repos/<域名>/<仓库名>
git reset --hard HEAD
git clean -fd
git pull origin main

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/review_process.md (reported line 273)May include surrounding context.

md
- **检查项**:元数据是否完整

#### 环境文件
- **检查项**:.env 文件是否被 .gitignore 排除
- **检查项**:环境变量模板文件(.env.example)是否提供

#### 其他配置文件

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The workflow explicitly instructs scheduled runs to discard uncommitted local changes before proceeding, but provides no user warning, opt-in requirement, backup step, or safety guard. In a code-review skill that operates on local repositories, this can destroy user work or unrelated in-progress changes and is especially risky because scheduled execution may happen without interactive confirmation.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The workflow includes saving reports plus attempting remote git commit and push, but does not require a clear warning or approval for repository mutation and outbound publication. In skill context, this is especially dangerous because a code-review tool is expected to inspect code, not silently publish changes or potentially leak findings to a remote origin.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

This is a true tool-abuse risk because the workflow prescribes dangerous git commands (git reset --hard and git clean -fd) based only on repository state, without validating that the target path is a dedicated disposable checkout or obtaining approval. In the context of a code-review skill that clones and reuses local repositories, this is more dangerous because an attacker or misconfiguration could steer the workflow toward a sensitive working tree and cause irreversible data loss during automated execution.

Content

Scanner excerpt · workflows/scheduled_workflow.md (reported line 28)May include surrounding context.

md
- 进入本地绝对路径。
- 检查本地仓库是否有未提交的修改(`git status --short`)。
  - 若有修改:自动执行 `git reset --hard HEAD` 与 `git clean -fd` 撤销所有本地修改。
- 检查仓库是否存在 tag 标签:
  - 存在 tag:获取本地最新 tag,进入步骤 3。
  - 不存在 tag:获取本地 HEAD,进入步骤 4。

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The FAQ recommends automatically checking or generating SSH keys and sending them to the user, but gives no warning about handling private key material, passphrases, destination validation, or safer alternatives. In a code-review skill that interacts with repositories, credential-generation automation is sensitive and can expose authentication secrets or encourage insecure key management workflows.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description includes broad trigger phrases such as '检查代码质量', '审查报告', and instructions to use the skill whenever the user mentions using the skill itself. These can overlap with ordinary discussion or high-level requests, causing the agent to invoke a workflow that may clone repositories or modify local files without sufficiently explicit user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly supports cloning repositories, installing dependencies, generating reports, and automatically moving files between directories, but the entry document does not present clear user-facing warnings or consent gates for these side effects. In an agent setting, this increases the risk of unexpected network access, filesystem changes, or execution of untrusted project setup steps when a user intended only a discussion or review plan.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

SQP-3 applies to all file types and flags language/locale policy violations. This markdown skill guidance forces a specific language for all readers, and the file does not mention that Chinese is optional, user-selected, or required for a region-specific purpose.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.