Back to skill

Security audit

java-code-review

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed GitLab Java code-review workflow with user-confirmed merge support, but users should treat its repository-write examples and token handling carefully.

Install only if you want a Chinese-language Java/GitLab code-review workflow that may use GitLab credentials. Use a least-privilege token, verify project and branch names, prefer merge requests over direct merges, and require clear confirmation before any repository-changing action.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (8)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 225)May include surrounding context.

md
- [checklist.md](references/checklist.md) - 完整检查清单

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger phrases are broad terms like code review, merge code, and branch merge, which are common in normal developer conversations. In a skill that can eventually perform GitLab write actions, overly broad invocation criteria raise the risk of accidental activation, causing unintended repository access, report generation, or merge-side effects.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The instruction requires package names to use the hardcoded prefix "cn.ctg.travel.{项目名}" for all reviewed code. This is a natural-language policy constraint that forces a specific organizational/locale convention without stating that the skill is limited to that organization or offering any user choice.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill is framed as a code review capability, but it also authorizes write operations that can create merge requests or directly create commits. That expands the skill from analysis into repository mutation, increasing the chance of unintended or overly trusted code changes if the skill is invoked in the wrong context or with insufficient confirmation controls.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The file title and checklist content are written in Chinese and present the review standard as a fixed requirement, but there is no indication that users may choose another language or that the skill is limited to a Chinese-speaking or region-specific context. Under the policy, forcing a specific language without opt-in is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document includes concrete write-capable GitLab API examples for accepting merge requests and directly merging branches, but it does not warn that these operations change repository state and should require explicit user confirmation, authorization checks, and caution around protected branches. In the context of an agent skill that can review code and then merge branches, this omission increases the risk that an automated workflow could perform irreversible or unauthorized merges based on ambiguous prompts or unsafe defaults.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

L071 明确写明“严禁处理文件流”,表达的是禁止文件相关处理;但 L221 又要求将 CR 报告保存到 task/codereview/{日期}/ 目录,这至少意味着生成并写入文件。两处文档对技能是否进行文件输出存在直接意图冲突。

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The authentication section shows realistic token header formats, including a token-looking prefix, without any warning that these values are sensitive secrets and must never be hardcoded, committed, logged, or echoed in reports. In a code-review-and-merge skill, this is more dangerous because users may copy examples directly into scripts or prompts, leading to credential exposure in automation logs, documentation, or repositories.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.