Back to skill

Security audit

Git Workflow Cn

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward Chinese Git workflow reference, but users should be careful because it includes destructive Git cleanup and reset commands.

Install only if you want a Git command reference. Before running commands from it, verify the target repository and branch, prefer dry-run or backup steps, and treat reset --hard, git clean -f, filter-branch, remote branch deletion, and pushes to main/staging/production as potentially destructive.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 207)May include surrounding context.

md
# 2. 开发并提交
git add .
git commit -m "feat: 添加登录功能"
git push origin feature/login

# 3. 创建 Pull Request
# 4. Code Review

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
94% confidence
Finding

git reset --hard HEAD~1 is a destructive parameterization of a powerful tool that can delete local work immediately. In an agent skill, presenting this command without guardrails can cause accidental data loss if a user follows it without understanding that both index and working tree changes may be discarded.

Content

Scanner excerpt · SKILL.md (reported line 303)May include surrounding context.

md
git reset --soft HEAD~1

# 撤销最近提交(丢弃修改)
git reset --hard HEAD~1

# 修改最近提交信息
git commit --amend -m "新信息"

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Using git reset --hard COMMIT_ID to restore deleted commits rewrites the current branch and forces the working tree to match the target commit, which can wipe out current local changes and detach users from later history if misunderstood. In documentation meant for broad developer use, this is dangerous when not paired with warnings, recovery notes, or safer restoration patterns.

Content

Scanner excerpt · SKILL.md (reported line 330)May include surrounding context.

md
# 恢复删除的提交
git reflog                        # 查找提交
git reset --hard COMMIT_ID        # 恢复

# 恢复删除的分支
git reflog                        # 找到分支最后的提交

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill documents git reset --hard HEAD~1, which irreversibly discards uncommitted changes and rewrites the working tree without any prominent warning, confirmation step, or safer alternative first. In an agent-assistance context, users may copy commands verbatim, so omission of data-loss warnings materially increases the chance of accidental destructive use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The repository-cleaning section includes destructive commands such as git clean -f, git clean -fd, history-rewriting via git filter-branch, and aggressive garbage collection, but does not clearly warn that these can permanently delete files and alter repository history. In a workflow skill, these commands are especially risky because they are operational guidance likely to be executed directly by users.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.