Back to skill

Security audit

Convert Github Repository

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed repository conversion/export helper, but users should handle private repositories and generated exports carefully because they may contain sensitive code or issue data.

Install only if you want an agent to inspect and export repositories you specify. For private repositories, use a least-privilege GitHub token, review generated files for secrets or confidential issue/PR content, and choose an output location that will not overwrite important data.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (18)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says this skill should be used to convert/export GitHub repositories into other representations. However, the code chunk contains only a test harness for auditing a skill repository’s metadata, documentation, and file layout. Its primary behavior is QA/compliance checking for skill packaging, not repository transformation. This is a material purpose mismatch, not just an implementation detail.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The README leaves the trigger condition as a placeholder ('When triggered: [trigger condition]') instead of defining clear activation boundaries. In an agent skill, ambiguous triggering can cause the skill to run in unintended contexts, increasing the chance of processing sensitive repositories or taking actions the user did not mean to invoke.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The README advertises a '--mode write' operation but provides no warning about filesystem changes, overwrite behavior, or the need for user confirmation. In a repository-conversion skill, undocumented write capability can lead to accidental modification of local files or generated outputs in sensitive directories, especially if an agent invokes the mode automatically.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README states "触发条件: [trigger condition]" without defining any actual trigger phrase, scope, or exclusion conditions. For a markdown file, this creates an ambiguous activation description that could lead to unintended or inconsistent skill invocation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation shows --mode read and --mode write operations, which imply a generic file reader/writer workflow rather than converting a GitHub repository into Markdown, JSON, CSV, or another representation. This actively conflicts with the manifest's declared intent of repository conversion/export, making the documentation misleading about what the skill is supposed to do.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Documenting a write mode without any warning about filesystem or data modification can lead users or downstream agents to run the skill in a destructive context without understanding side effects. In a repository-conversion skill, unclear write behavior is more dangerous because it may overwrite source files, generated artifacts, or other local data paths during automated workflows.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The README states that an API_KEY is mandatory, but neither the manifest description nor the surrounding documentation explains any external service dependency. For a skill presented as converting a GitHub repository URL or local repository path into other formats, requiring a generic service API key contradicts the documented intent and suggests different behavior than advertised.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill declares capabilities to read local repositories and interact with git, but it does not define an explicit tool/permission scope. That omission weakens least-privilege controls and can let an agent invoke broader file access than users expect when handling local repo paths.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill is designed to export repository text, metadata, and issue/PR bodies wholesale, which can include secrets, internal notes, tokens, credentials, or sensitive business information already present in the repo. Because it does not require sensitivity checks or user confirmation for bulk export, it materially increases the risk of mass disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs use of GITHUB_TOKEN and remote GitHub API calls without a clear user-facing disclosure that repository metadata and possibly content will be transmitted to GitHub and authenticated with the user's token. In a local-repo conversion context, that can surprise users and lead to unintended external sharing or credential use.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 88)May include surrounding context.

For remote repos, call GitHub API:

text
GET https://api.github.com/repos/{owner}/{repo}
Authorization: Bearer {GITHUB_TOKEN}
Accept: application/vnd.github+json

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 102)May include surrounding context.

For remote repos, call GitHub API:

text
GET https://api.github.com/repos/{owner}/{repo}
Authorization: Bearer {GITHUB_TOKEN}
Accept: application/vnd.github+json

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill describes creating converted files, directory READMEs, and an output path on disk, but it does not clearly warn users that running the conversion will write potentially large amounts of data locally. Unexpected writes can overwrite files, consume storage, or persist sensitive repository content in new locations.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The JSON mode explicitly instructs inclusion of text file contents and even large-file encoding, enabling bulk serialization of a repository into a portable format that is easy to exfiltrate or redistribute. In practice, this amplifies the impact of any sensitive material present in the repository because it packages large amounts of content into a single extractable artifact.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The test test_readme_zh_exists requires README_zh.md to exist, which is a natural-language locale requirement embedded in code. This imposes a specific language/localization expectation without any visible opt-in, alternative, or justification that the skill is region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The instruction "Keep SKILL.md body in English" imposes a language requirement in natural-language project policy. Under the stated rule, forcing a specific language without opt-in is a locale/language policy concern, and this requirement is repeated as a standard elsewhere in the file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This line explicitly enforces English for both the SKILL.md body and reference documentation. Because the rule flags language-policy constraints that force a specific language without user opt-in or documented justification, this is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

Requiring an API credential without guidance on secure handling increases the chance that users place secrets in command lines, plaintext configs, or repositories, leading to credential leakage. This is made more suspicious by the mismatch between the skill’s described purpose and the stated need for an API key, which could prompt unnecessary secret exposure.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.