Back to skill

Security audit

release-flow

Security checks for vulnerabilities and agentic risk

Overview

This is a project-specific Git release helper, but it needs review because it can push production code and uses branch/user values in Bash commands without clear safety validation.

Install this only for the intended redfoxhub-html repository and only if you are comfortable letting the agent push to develop and master. Before any push or production release, review the printed command list, confirm the branch name contains only simple safe characters, and prefer protected branches or Merge Requests where available.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:60
Finding

Shell Command Injection Through Unvalidated Git-Derived Values

Content
View full analysis
/_` - `slug`: Extract the core noun from the user's description, use lowercase English with underscores, and limit it to 24 characters. - `gitUser`: Run `git config user.name` and use its value directly; if it contains spaces or uppercase characters, lowercase it and remove spaces. ``` The resulting value is inserted into a Bash command without mandatory validation or shell-safe argument handling: ```bash git status --porcelain git fetch origin git checkout master git pull --ff-only origin master git checkout -b /_ ``` The current branch name is also stored as `WORK_BRANCH` and inserted into multiple command templates: ```markdown 1. **Environment validation**: - `git rev-parse --abbrev-ref HEAD` must not be `master` or `develop`. - `git status --porcelain` must be empty. - Record the current branch name as `WORK_BRANCH`. ``` ```bash git push -u origin ``` ```bash git checkout develop git pull --ff-only origin develop git merge --no-ff git push origin develop ``` ```bash git checkout ``` The production workflow repeats the same unsafe pattern: ```bash git fetch origin git merge origin/master git push -u origin ``` ```bash git checkout master git pull --ff-only origin master git merge --no-ff git push origin master ``` ```bash git checkout ``` ### Technical Analysis The Skill directs the Agent to perform all Git operations through Bash. Both `gitUser` and `WORK_BRANCH` origin ...[truncated 3037 chars]
Remediation
View remediation
Vulnerability Patterns
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
65% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 83)May include surrounding context.

md
### 失败兜底
- 工作区有改动 → 提示用户先 `git stash` 或先 commit,**不要替用户做**。
- `git pull --ff-only` 失败 → 说明本地 master 已分叉,告知用户原因,让用户决定是否 `git reset --hard origin/master`,Agent 不强行 reset。
- `git config user.name` 为空 → 提示用户配置后重试,临时使用 `dev` 作为后缀。

---

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The public constraints state that the workflow must use the actual git config user.name value directly and not generate extra abbreviations or suffixes. But the branch-generation step says to lowercase and strip spaces from gitUser, and even fall back to dev if unavailable, which is an active contradiction in the skill's own documented intent.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.