Back to skill

Security audit

GitHub Big Tech Latest Repo Explorer

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its repo-discovery purpose, but it automatically reads a local GitHub token file and uses that credential for GitHub API calls without clear user-facing disclosure.

Review this skill before installing if you keep GitHub credentials in ~/.openclaw/.env. It should be treated as able to read that token and use it for GitHub API calls, and it will store local repository history inside the skill directory. Prefer installing only if you are comfortable with that credential path or can run it with an intentionally limited GitHub token.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (13)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared purpose says the skill selects recent high-star repositories using specific date and star thresholds, but the analyzed behavior reportedly performs different actions including local config reads and concurrent network probing of GitHub org pages. This mismatch is dangerous because operators and policy systems may trust the description while the skill actually performs broader reconnaissance-like activity and omits the promised filtering logic.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest says the skill should use a default 90-day window and require stars >1000, only expanding the time window when no repositories satisfy that condition. This history file shows many repositories with stars well under 1000 (including 0, single digits, and hundreds) being recorded as shown, indicating actual behavior does not match the stated filtering rule.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
94% confidence
Finding

The script explicitly reads a GitHub token from ~/.openclaw/.env when environment variables are unavailable, bypassing a host safeguard that filters token-like environment variables. In an agent-skill context, this broadens the script's ability to access sensitive credentials from the local filesystem and use them for outbound authenticated API requests, which is dangerous if the skill is untrusted or modified.

Content

Scanner excerpt · scripts/fetch_repo.py (reported line 143)May include surrounding context.

python
# ---------- GitHub API ----------

def _env_file_token() -> str:
    """从 ~/.openclaw/.env 读 GITHUB_TOKEN(OpenClaw exec 快照会过滤 token 类环境变量,故需文件回退)。"""
    env_file = os.path.expanduser("~/.openclaw/.env")
    try:
        with open(env_file, "r", encoding="utf-8") as f:

Credential Access

High
Category
Privilege Escalation
Confidence
94% confidence
Finding

This finding is the same credential-access behavior centered on the hardcoded ~/.openclaw/.env path. In this skill context, reading secrets from a predictable local file makes the code more dangerous because the skill is designed to run automatically and then transmit authenticated requests to GitHub, creating a clear path from local secret access to external use.

Content

Scanner excerpt · scripts/fetch_repo.py (reported line 144)May include surrounding context.

python
def _env_file_token() -> str:
    """从 ~/.openclaw/.env 读 GITHUB_TOKEN(OpenClaw exec 快照会过滤 token 类环境变量,故需文件回退)。"""
    env_file = os.path.expanduser("~/.openclaw/.env")
    try:
        with open(env_file, "r", encoding="utf-8") as f:
            for line in f:

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill declares no explicit tool scope even though its documented and inferred behavior involves environment access, local file read/write, and network operations. Without a least-privilege declaration, an agent may execute the skill with broader capabilities than necessary, increasing the blast radius if the skill is misused or behaves unexpectedly.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The natural-language content of the skill is written entirely in Chinese, including the user-facing description and operational instructions, with no indication that language selection is optional. Under the policy, forcing a specific language or locale without user opt-in is a natural-language policy violation unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The document title and all output instructions require generating answers in Chinese, but there is no indication that the user can choose another language or that the skill is intentionally limited to a Chinese-only context. This is a natural-language policy concern because it imposes a locale/language constraint without opt-in.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The top-level docstring says the script will 'pick one (random) that has not been shown before'. In practice, the CLI default is --pick=stars, and main() passes that strategy into pick_unseen, so the actual default behavior is deterministic highest-star selection, not random choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code emits user-facing messages in Chinese, and the same language constraint continues throughout the script's help and rendered output. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The script includes Chinese-only docstrings and user-facing content, including argument help text and output sections later in the file. Because the skill does not offer a language choice or document a justified locale limitation, this violates the language/locale policy.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The rendered summary always states the chosen repository is '在未输出候选中 stars 最多', which is only true when --pick=stars. The code explicitly supports oldest and random strategies via pick_unseen(..., strategy=args.pick), so this inline documentation/output can actively misrepresent why a repo was selected.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest says the skill is for finding repositories within a default 90-day window and requiring stars >1000, expanding the time window when no repositories match. This file does not implement any repository recency filtering or star-threshold logic; it reads a local organization list, visits organization/profile pages, and heuristically checks for repository presence by parsing HTML.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The docstring states '只做轻量 HTTP GET,不下载完整 HTML' ('only lightweight HTTP GET, does not download full HTML'). In practice, the code performs normal GET requests and reads substantial portions of the HTML body via resp.read(max_bytes) for both profile and repository pages, which is an active contradiction rather than a mere omission.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.