Back to skill

Security audit

GitHub仓库深度解读器

Security checks for vulnerabilities and agentic risk

Overview

This GitHub analysis skill is broadly coherent, but its workflow builds shell commands from untrusted repository data in ways that could let crafted input run unintended local commands.

Review this skill before installing. It is meant for public GitHub repository analysis, but avoid running it on private or sensitive repositories unless the workflow is revised to validate repo names, avoid shell interpolation, use unique secure temp directories, and clearly confirm external data sharing before summarization or community search.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
workflow.json:23
Finding

Shell Command Injection Through Unvalidated Repository Identifiers

Content
View full analysis

Vulnerability Details

File Location: workflow.json, lines 23-25
Vulnerability Type: OS command injection through unsafe placeholder interpolation
Risk Level: High

Vulnerable Code

json
"commands": [
  "gh repo view {owner}/{repo} --json name,description,language,stargazerCount,pushedAt,license",
  "gh api repos/{owner}/{repo}/languages --jq '.'",
  "gh api repos/{owner}/{repo}/contents --jq 'map({name, type})'"
]

Related command templates using the same placeholders also appear at lines 39, 53, and 83-85.

Technical Analysis

The workflow inserts the user-provided owner and repo variables directly into shell command strings. No allowlist validation, escaping procedure, or structured argument construction is defined.

If the workflow engine executes these command strings through a shell, repository identifiers containing shell metacharacters can alter the command structure. Quoting the URL in some related templates does not provide complete protection because an attacker may supply quote characters, command substitutions, or other shell syntax capable of leaving the intended quoting context.

Repository identifiers should be treated as untrusted input even when they are normally expected to follow GitHub naming rules. The workflow does not enforce those rules before command construction.

Attack Path

  1. An attacker supplies a specially crafted repository owner or repository name through a supported trigger.
  2. The workflow substitutes that value into one or more command templates.
  3. The resulting command string is passed to a shell.
  4. Embedded shell syntax terminates or modifies the intended gh command.
  5. The injected command executes with the privileges and environment of the Agent process.

Impact Assessment

Successful exploitation can provide arbitrary command execution under the account running the workflow. The attacker could read files accessible to that acc ...[truncated 358 chars]

Remediation
View remediation

Remediation Suggestions

  • Do not build executable shell strings from user-controlled values.
  • Invoke gh through a process API that accepts an argument array, with shell execution disabled.
  • Validate owner and repo before use against strict GitHub-compatible allowlists.
  • Reject whitespace, quote characters, path separators outside the expected delimiter, command substitutions, control characters, and shell metacharacters.
  • Construct API paths with a URL/path encoding library rather than textual concatenation.
  • Apply the same correction to all related templates at lines 39, 53, and 83-85.
  • Run the workflow under a minimally privileged account without unnecessary filesystem access or sensitive environment variables.
  • Add tests containing quotes, semicolons, substitutions, newlines, and other adversarial input to verify that each value remains one literal process argument.

T09 · Insecure Skill Coding Practices

Error
Location
workflow.json:99
Finding

Command Injection and Output Path Manipulation in Card Rendering

Content
View full analysis

Vulnerability Details

File Location: workflow.json, lines 99-100
Vulnerability Type: OS command injection and unsafe output-path construction
Risk Level: High

Vulnerable Code

json
"commands": [
  "python3 scripts/render_mac_pro_card.py --title '{repo_name}' --subtitle '{one_line_description}' --stars '{star_count}' --lang '{primary_language}' --output /tmp/{repo_name}_cover.png",
  "python3 scripts/render_mac_pro_card.py --content '{architecture_summary}' --output /tmp/{repo_name}_detail.png"
]

Technical Analysis

Repository-derived and generated values are inserted into single-quoted shell arguments. A single quote in repo_name, one_line_description, primary_language, or architecture_summary can terminate the expected quoting context. Additional shell syntax can then be interpreted as a separate command or redirection when the template is executed through a shell.

The repo_name placeholder is also used unquoted in output paths. Consequently, shell metacharacters can affect command parsing, while path separators or traversal sequences can cause output to be written outside the intended location. Generated AI summary text must also be considered untrusted because it may preserve or transform adversarial repository content.

Attack Path

  1. An attacker controls repository metadata or repository content consumed by the analysis.
  2. That data influences a renderer field such as the repository name, description, or architecture summary.
  3. The workflow directly substitutes the resulting text into the renderer command.
  4. A quote or shell metacharacter escapes the intended argument boundary.
  5. The shell executes attacker-controlled syntax, or the crafted output name redirects file creation to an unintended path.

Impact Assessment

Command-injection exploitation can execute arbitrary commands with the Agent process's privileges. This may expose readable files, credentials, ...[truncated 316 chars]

Remediation
View remediation

Remediation Suggestions

  • Execute Python directly with a structured argument vector and disable shell interpretation.
  • Treat every metadata field and generated summary as untrusted data.
  • Generate output filenames from a server-controlled identifier or a strictly sanitized slug rather than the raw repository name.
  • Restrict filenames to a conservative character set and reject path separators, traversal components, control characters, and shell metacharacters.
  • Resolve and verify output paths against a dedicated per-run directory before writing.
  • Create that directory with restrictive permissions and refuse to follow symbolic links.
  • Pass long generated content through standard input or a securely created data file instead of interpolating it into a command string.
  • Add adversarial tests covering single quotes, substitutions, semicolons, newlines, path traversal, and option-like values.

T09 · Insecure Skill Coding Practices

Warning
Location
workflow.json:39
Finding

Predictable Shared Temporary File Enables Symlink and Cross-Run Attacks

Content
View full analysis

Vulnerability Details

File Location: workflow.json, lines 39-52
Vulnerability Type: Insecure temporary-file handling
Risk Level: Medium

Vulnerable Code

json
"commands": [
  "gh api repos/{owner}/{repo}/readme --jq '.content' | base64 -d > /tmp/repo_readme.md"
],
"output": {
  "readme": "README.md original content",
  "readmeFile": "/tmp/repo_readme.md"
}

The file is subsequently consumed by:

json
"commands": [
  "summarize /tmp/repo_readme.md --model google/gemini-3-flash-preview",
  "summarize \"https://github.com/{owner}/{repo}\" --model google/gemini-3-flash-preview"
]

Technical Analysis

Every workflow run writes to the same predictable path, /tmp/repo_readme.md. Shared temporary directories are commonly writable by multiple local users and processes. The workflow does not create the file atomically, verify its ownership or type, prevent symbolic-link traversal, or isolate concurrent executions.

A local attacker may pre-create the path as a symbolic link before redirection occurs. Depending on permissions, shell redirection could overwrite the symlink target. An attacker may also replace the file after it is written but before summarize reads it, creating a time-of-check/time-of-use race. Concurrent legitimate runs can similarly overwrite one another and cause one repository's content to be analyzed in another run.

Attack Path

  1. A local attacker predicts the fixed path /tmp/repo_readme.md.
  2. The attacker creates a symbolic link at that path or repeatedly replaces the file during workflow execution.
  3. The workflow redirects decoded README content to the attacker-prepared path.
  4. If the path is a permitted symbolic-link target, an unintended file is overwritten.
  5. Alternatively, the attacker replaces the temporary file before the summarization step.
  6. The workflow then summarizes attacker-controlled content or content belonging to another ...[truncated 492 chars]
Remediation
View remediation

Remediation Suggestions

  • Create a unique per-run directory using a secure temporary-directory API such as mkdtemp.
  • Set directory and file permissions so only the workflow account can access them.
  • Create files atomically with exclusive-create and no-follow protections.
  • Avoid fixed names in globally writable directories.
  • Pass the securely generated path between workflow steps as structured state rather than hardcoding it.
  • Confirm that the path remains inside the per-run directory and that it is a regular file owned by the expected account before reading.
  • Remove temporary files and directories in a guaranteed cleanup block after success or failure.
  • Isolate simultaneous workflow executions so files cannot be shared across runs.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The workflow sends repository content and metadata to external services, including a summarization model and an external search/aggregation service, without clearly warning the user about data egress. This is particularly risky because repository READMEs, metadata, and derived analysis may contain sensitive or proprietary information, and the workflow also claims to handle private-repo cases, increasing the chance that users may attempt analysis on non-public targets.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly describes generating structured reports and supports extensions that can publish or sync derived content to external destinations such as Wiki and Obsidian, but it does not warn users about disclosure, copyright, confidentiality, or reputational risks from republishing AI-generated summaries. This can cause users to unintentionally distribute inaccurate, sensitive, or license-constrained content beyond the original analysis context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The name, description, category, and trigger phrases are all presented only in Chinese, and the skill does not offer an opt-in or alternative language mode. This can be a language/locale policy issue when users are not given a choice of operating language.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger list is very broad and maps to common developer requests such as repository analysis and architecture interpretation, which can cause the skill to activate in situations the user did not explicitly intend. In a skill that performs multi-step external lookups and content generation, ambiguous activation increases the chance of unintended data access, network calls, and workflow execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly retrieves repository data, README contents, and community discussions from external services including GitHub, Twitter, and Reddit, but it does not clearly warn the user that their input and derived queries will be sent over the network. This creates privacy and consent risk, especially if users supply private repository URLs, internal project names, or sensitive comparison targets expecting local-only analysis.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest presents the skill description, category, channels, step names, and trigger phrases entirely in Chinese, which implies a locale-specific interaction model. There is no explicit user opt-in, language selection, or documentation that this workflow is intentionally restricted to Chinese-speaking users.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The workflow executes shell-style commands and writes files under /tmp, but the manifest does not clearly warn users that local subprocess execution and filesystem writes will occur. This is dangerous because users may expect passive analysis, while the skill actually performs active command execution that could have side effects, consume credentials configured for gh, or create artifacts on the host.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad enough to activate on ordinary research or comparison requests, which can cause the workflow to run data collection, external lookups, and local file-writing steps without the user clearly intending this specific automation. In this skill's context, overbroad activation is more dangerous because the workflow chains multiple capabilities, including GitHub API access, third-party summarization, external sentiment gathering, and image generation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README presents the skill behavior entirely in Chinese and describes the generated outputs in Chinese-oriented terms, with no indication that users may choose another language. Under the policy, forcing a specific language or locale without user opt-in is a natural-language policy violation unless the constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.