Back to skill

Security audit

GitCode API Usage

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a legitimate GitCode SDK helper, but it installs an unpinned package and exposes broad authenticated GitCode operations without enough guardrails for destructive actions.

Review before installing. Use a dedicated virtual environment, pin and verify the `gitcode-api` package version, and use a least-privilege short-lived GitCode token from an environment variable or secret store rather than `--api-key`. Confirm the exact owner/repo and intended operation before using delete, transfer, member, webhook, OAuth, key, merge, or file upload/update methods.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:22
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:22-26; duplicated in references/api-reference.md:3-7 and references/workflow-patterns.md:3-9
Vulnerability Type: Unpinned dependency and software supply-chain exposure
Risk Level: Medium

Vulnerable Code:

markdown
Use the published Python package:

```bash
pip install -U gitcode-api
text

The same installation pattern appears in the reference documentation:

```bash
pip install -U gitcode-api

Technical Analysis

The Skill directs users to install or upgrade gitcode-api without specifying an audited version or verifying package integrity. The -U option explicitly selects a newer compatible release, meaning the code ultimately installed can change after this Skill has been reviewed.

Python package installation may execute package build or installation logic. Moreover, imported package code runs with the privileges of the invoking Python process. Because no exact version, lock file, artifact hash, or signature verification is specified, the reviewed Skill cannot guarantee that a future downloaded artifact has the same behavior as the currently expected package.

This is a supply-chain weakness rather than evidence that the current gitcode-api package is malicious.

Attack Path

  1. An attacker compromises the package publisher account, package repository, release pipeline, or an upstream dependency.
  2. The attacker publishes a malicious release that satisfies the unpinned installation command.
  3. A user follows the Skill instructions and executes pip install -U gitcode-api.
  4. Pip downloads the attacker-controlled release and may execute its build or installation code.
  5. The malicious package subsequently executes again when imported by the bundled scripts.
  6. The payload runs with the user's privileges and may access environment variables, including GITCODE_ACCESS_TOKEN, as well as files and network resources avail ...[truncated 618 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the dependency to a specifically reviewed release, for example:

    bash
    python -m pip install gitcode-api==<audited-version>
    
  2. Publish a requirements or lock file containing exact transitive dependency versions.

  3. Require verified package hashes with pip's --require-hashes option.

  4. Install into a dedicated virtual environment rather than the global interpreter.

  5. Remove -U from routine setup instructions so an existing audited version is not silently replaced.

  6. Document a controlled upgrade process that includes source review, vulnerability scanning, and artifact verification.

  7. Keep the existing requirement to obtain user confirmation before installation, but explicitly show the exact package version and source to be installed.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/gitcode_api_cli.py:21
Finding

GitCode Access Token Accepted Through Command-Line Arguments

Content
View full analysis

Vulnerability Details

File Location: scripts/gitcode_api_cli.py:21-25 and scripts/gitcode_api_cli.py:60-63
Vulnerability Type: Sensitive credential exposure through process arguments
Risk Level: Medium

Vulnerable Code:

python
def build_client(args: argparse.Namespace) -> GitCode:
    return GitCode(
        api_key=args.api_key or os.getenv("GITCODE_ACCESS_TOKEN"),
        owner=getattr(args, "owner", None),
        repo=getattr(args, "repo", None),
    )
python
def make_parser() -> argparse.ArgumentParser:
    parser = argparse.ArgumentParser(description="Run common gitcode-api SDK operations.")
    parser.add_argument("--api-key", help="GitCode access token. Defaults to GITCODE_ACCESS_TOKEN.")

Technical Analysis

The legacy CLI accepts a GitCode access token through the --api-key command-line option. Command-line arguments are not an appropriate secret transport mechanism because they can be exposed through shell history, process inspection utilities, operating-system process metadata, audit systems, job schedulers, diagnostic reports, terminal logging, and wrapper telemetry.

The implementation passes the argument directly to the SDK and does not print it itself. The project documentation also advises users to prefer environment variables for production. Nevertheless, retaining the option creates an easily misused credential interface, and the argument may be exposed before the Python process can protect or discard it.

Attack Path

  1. A user invokes the helper with a command such as:

    bash
    python scripts/gitcode_api_cli.py --api-key SECRET me
    
  2. The shell may retain the complete command in its history.

  3. While the process is running, another local user or monitoring agent with sufficient process-observation permissions may inspect its arguments.

  4. Alternatively, CI logs, audit records, terminal capture, or wrapper telemetry records th ...[truncated 813 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the --api-key argument and accept credentials only through a safer mechanism such as GITCODE_ACCESS_TOKEN, a protected credential file, an operating-system secret store, or an interactive hidden prompt.
  2. If backward compatibility is required, reject --api-key with a migration message rather than continuing to consume its value.
  3. For interactive use, retrieve the token with getpass.getpass() so it is not echoed or placed in shell history.
  4. Ensure credential files are restricted to the owning user and are excluded from version control.
  5. Document least-privilege token scopes and recommend short-lived tokens where supported.
  6. Advise users who previously supplied tokens through argv to remove affected shell history and logs and rotate those tokens.
  7. Avoid including tokens in exceptions, debug output, telemetry, or CI command echoing.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (7)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/check_env.py (reported line 28)May include surrounding context.

python
print("GITCODE_ACCESS_TOKEN: set")
    else:
        print("GITCODE_ACCESS_TOKEN: missing")
        print("set it with: export GITCODE_ACCESS_TOKEN='your-token', or use .env files")

    print("top-level clients: GitCode, AsyncGitCode")
    return 0

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/gitcode_api_cli.py (reported line 69)May include surrounding context.

python
def make_parser() -> argparse.ArgumentParser:
    parser = argparse.ArgumentParser(description="Run common gitcode-api SDK operations.")
    parser.add_argument("--api-key", help="GitCode access token. Defaults to GITCODE_ACCESS_TOKEN.")

    subparsers = parser.add_subparsers(dest="command", required=True)

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-reference.md (reported line 20)May include surrounding context.

md
Base transport defaults:

- Base URL: `https://api.gitcode.com/api/v5`
- Token env var: `GITCODE_ACCESS_TOKEN`
- Default timeout: `30.0`
- Transport: `httpx.Client` / `httpx.AsyncClient`

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-reference.md (reported line 91)May include surrounding context.

md
Base transport defaults:

- Base URL: `https://api.gitcode.com/api/v5`
- Token env var: `GITCODE_ACCESS_TOKEN`
- Default timeout: `30.0`
- Transport: `httpx.Client` / `httpx.AsyncClient`

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-reference.md (reported line 115)May include surrounding context.

md
Base transport defaults:

- Base URL: `https://api.gitcode.com/api/v5`
- Token env var: `GITCODE_ACCESS_TOKEN`
- Default timeout: `30.0`
- Transport: `httpx.Client` / `httpx.AsyncClient`

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This markdown file enumerates many mutating or destructive operations such as deleting repositories and contents, transferring repositories, removing members, merging pull requests, and modifying tags/webhooks, but it provides no warning that these actions can alter or permanently affect remote user data. For markdown files, SQP-2 applies when the skill description omits warnings about behaviors affecting user data, privacy, or system integrity.

Content

No source excerpt is available for this finding.

Cloud Storage Exfiltration

Medium
Category
Data Exfiltration
Confidence
55% confidence
Finding

Data is uploaded to cloud storage (S3 / GCS / Azure Blob). This may be a legitimate backup or exfiltration to an external bucket. Manual review is recommended.

Content

Scanner excerpt · references/api-reference.md (reported line 205)May include surrounding context.

md
- `client.repos.update_push_config()`
- `client.repos.get_push_config()`
- `client.repos.upload_image()`
- `client.repos.upload_file()`
- `client.repos.update_repo_settings()`
- `client.repos.get_repo_settings()`
- `client.repos.get_pull_request_settings()`

Static analysis

No suspicious patterns detected.