Back to skill

Security audit

GCCEO

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly CEO/business training content, but it ships publishing instructions and a script that ask for broad GitHub credentials and can mutate a GitHub account.

Review before installing. Do not run publish.sh or follow the PAT publishing guide unless you are intentionally publishing this exact project and understand the GitHub account effects. Prefer GitHub CLI or a fine-grained, short-lived token scoped only to the target repository, verify the exact publisher/source, and treat any full-scan report output as sensitive business data.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
PUBLISH_GUIDE.md:12
Finding

Excessively Privileged GitHub Personal Access Token Instructions

Content
View full analysis

Vulnerability Details

File Location: PUBLISH_GUIDE.md, lines 12-20
Vulnerability Type: Excessive credential permissions and violation of least privilege
Risk Level: Medium

Vulnerable Code Snippet

The guide instructs users to generate a classic GitHub token with the following permissions:

text
Generate new token (classic)

Permissions:
- repo (Full control of private repositories)
- read:org (Read organization and team membership)

Generate token
Copy the token immediately because it is displayed only once.

Technical Analysis

The documented operation is publishing a single public repository. It does not require a classic personal access token with full control over every private repository accessible by the user. Organization membership access is also not shown to be necessary.

Classic tokens using the repo scope provide broad access that is not restricted to the project being published. If the token is exposed through shell history, Git credential storage, terminal logging, malware, a compromised credential helper, or another local process, an attacker may use it against unrelated repositories.

The read:org permission additionally exposes organization and team membership information. This can assist reconnaissance and targeted attacks even if the organization data is not directly modified.

Attack Path

  1. A user follows the publishing guide and creates a classic personal access token.
  2. The user grants the recommended repo and read:org scopes.
  3. The token is entered during Git authentication and may be retained by a credential helper or exposed to a compromised local process.
  4. An attacker extracts the token from the affected environment.
  5. The attacker authenticates to GitHub using the token.
  6. The attacker accesses or modifies unrelated private repositories available to the victim and enumerates organization membership data.
  7. Depending on the victim's r ...[truncated 683 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace the classic PAT instructions with a fine-grained personal access token.
  2. Restrict the token to the single target repository.
  3. Grant only the minimum repository permissions required to push content, such as narrowly scoped Contents write access.
  4. Remove read:org unless a documented publishing operation specifically requires it.
  5. Configure a short expiration period and require token rotation.
  6. Prefer gh auth login or an approved Git credential manager rather than manually handling tokens as passwords.
  7. Warn users not to place tokens in repository files, command-line arguments, shell history, or plaintext configuration.
  8. Document immediate revocation procedures for suspected exposure.
  9. Where practical, use a dedicated publishing workflow with environment protection and repository-scoped credentials.

T08 · Insecure Dependencies

Warning
Location
README.md:69
Finding

Unpinned and Inconsistent Skill Installation Sources

Content
View full analysis

Vulnerability Details

File Locations:

  • README.md, lines 69-79
  • SKILL.md, lines 21-23 and 738-747

Vulnerability Type: Mutable and inconsistent third-party installation sources
Risk Level: Medium

Vulnerable Code Snippet

README.md provides unversioned registry installation commands and identifies one GitHub owner:

bash
# Install from ClawHub (after publish)
openclaw skills install gceo-global-ceo-skill-system

# Install from GitHub
git clone https://github.com/yjkj999999/GCCEO-GlobalCEO-Skill-System.git

# Install from SkillHub (after publish)
skill install gceo

SKILL.md provides different unversioned package identifiers and a repository under another GitHub owner:

bash
# ClawHub
claw install gceo

# GitHub
git clone https://github.com/GCCEO/GCCEO-GlobalCEO-Skill-System.git

# SkillHub
skill install gceo

The metadata identifies yet another expected source relationship:

yaml
repository: https://github.com/yjkj999999/GCCEO-GlobalCEO-Skill-System
clawhub: https://clawhub.ai/yjkj999999/gceo-global-ceo-skill-system
skillhub: https://skillhub.ai

Technical Analysis

The installation instructions do not pin an immutable package version, Git tag, commit SHA, release digest, or checksum. Registry commands use short, mutable package identifiers, while GitHub installation alternates between the yjkj999999 and GCCEO owners.

This inconsistency prevents users from reliably determining which publisher and artifact were audited. A package registry entry, default branch, tag, or repository can change after review. If an unintended namespace is selected, compromised, reassigned, or controlled by another party, installation may retrieve content different from the audited project.

The direct git clone commands also retrieve the current default branch rather than an immutable revision. Consequently, a later repository compromise or malicious update can ...[truncated 1496 chars]

Remediation
View remediation

Remediation Suggestions

  1. Select one canonical GitHub organization or user and use it consistently in every file.
  2. Use one exact, verified ClawHub package identifier and one exact SkillHub package identifier.
  3. Pin registry installations to version 4.0.0 or another explicitly reviewed version using the package manager's supported syntax.
  4. Pin Git installations to an immutable commit SHA rather than the default branch.
  5. Publish cryptographic checksums or signed release attestations for downloadable artifacts.
  6. Verify release signatures and checksums before installation.
  7. Remove or correct the conflicting github.com/GCCEO/... and github.com/yjkj999999/... references.
  8. Document the verified publisher identity and expected repository URL next to every installation command.
  9. Add CI checks that reject inconsistent repository owners, package names, versions, and installation commands across documentation and metadata.
  10. Avoid advertising installation from unavailable or unverifiable registries until the corresponding package and publisher identity can be validated.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (11)

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

This section explicitly directs the user to generate a GitHub Personal Access Token with broad permissions including full repo access. Even though the document does not directly exfiltrate the token, requesting creation of a sensitive credential with excessive privileges creates a credential-access risk because compromise of that token would grant repository control.

Content

Scanner excerpt · PUBLISH_GUIDE.md (reported line 12)May include surrounding context.

md
## 方法一:命令行发布(推荐)

### Step 1: 生成 GitHub Personal Access Token (PAT)

1. 打开 https://github.com/settings/tokens
2. 点击 **"Generate new token (classic)"**

Credential Access

High
Category
Privilege Escalation
Confidence
92% confidence
Finding

Telling users to paste their Personal Access Token when prompted encourages direct handling of a sensitive secret in an interactive workflow without any safety caveats. In the context of an agent skill or copied instructions, this is more dangerous because users may follow the step inside monitored, logged, or untrusted environments, leading to credential leakage.

Content

Scanner excerpt · PUBLISH_GUIDE.md (reported line 36)May include surrounding context.

git push -u origin main

text

当提示输入密码时,粘贴您的 **Personal Access Token**(不是 GitHub 登录密码!)

### Step 3: 创建 GitHub Release

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description presents a business/leadership mastery skill, implying educational or advisory functionality. The actual code does not implement CEO training, content delivery, or business analysis. Instead, it performs DevOps/publishing actions against GitHub: checking authentication, creating a public repository, setting up remote publishing, and creating a release. These are materially different capabilities and access external resources (GitHub account/repo) not indicated by the description or declared permissions. Therefore this is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The guide instructs users to create a broad-scope GitHub Personal Access Token and paste it during authentication, but provides no warning about secure handling, scope minimization, storage, or revocation. This can normalize unsafe credential practices and increase the chance that a high-privilege token is exposed through terminal history, screenshots, clipboard managers, or reuse in the wrong prompt.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The description says the system is '为中国企业家量身打造', which imposes a specific regional/user-locale framing in the natural-language policy surface. The file does not present this as an opt-in regional mode or offer an alternative locale choice, so it can be read as a locale restriction rather than a documented optional specialization.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The invocation guidance advertises broad commands like domain-wide execution and full-system scans without any eligibility checks, scope limits, confirmation steps, or examples of when these commands should not be used. In an agent setting, such vague high-scope instructions can lead to over-collection, unintended actions, or use on sensitive enterprise contexts without informed operator consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documented full-scan command implies analysis of company information and generation of a report file, but it does not warn users that sensitive business data may be ingested, processed, or written to disk. This creates a real risk of confidentiality breaches, unauthorized handling of regulated data, and accidental exposure through generated artifacts such as report.html.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script automates creation of a GitHub repository and release using whatever GitHub CLI credentials are present on the host. That behavior is not aligned with the stated CEO-training purpose, so it creates an unnecessary capability for external publication and account-side effects that a user may not reasonably expect from this skill.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill contains GitHub automation capabilities that can create public repositories and releases under an authenticated user's account. In the context of a business education skill, this is unjustified functionality and increases the risk of unintended data publication, account misuse, and trust boundary violations if the script is run.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest includes a dedicated Chinese full-name field and the file broadly mixes English and Chinese labels throughout, but it does not indicate any user-selectable language preference or opt-in behavior. For a general-purpose global skill catalog, this can amount to a language/locale policy issue because the content appears to assume bilingual or Chinese presentation by default rather than documenting user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

Line L049 states the skill is 'for Chinese entrepreneurs,' which is a natural-language locale/audience restriction. The file does not explain this as an explicit opt-in or clearly justified region-specific compliance constraint, so it may violate the language/locale policy criterion.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.