Back to skill

Security audit

PR Doctor

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent PR-review purpose, but it can automatically create GitHub issues and retain review data without a clear confirmation gate.

Review this skill before installing. It is best used only where automatic GitHub issue creation is desired, GitHub permissions are narrowly scoped, and users understand that review findings may be saved locally in `.learnings/`. Prefer adding an explicit confirmation or dry-run step before issue creation and logging.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The workflow explicitly enables automatic GitHub issue creation but does not warn the user or require confirmation before modifying an external system. This creates a real risk of unauthorized or unexpected repository changes, spam issue creation, and disclosure of review findings into tracked systems if the workflow is triggered accidentally or with incomplete context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README explicitly describes automatic creation of GitHub Issues via gh api and writing learning records to .learnings/, but it does not warn that the skill may modify external systems or the local workspace. In an agent setting, this can lead to unintended side effects such as unauthorized issue spam, disclosure through issue content, or silent local file changes if a user expects read-only analysis.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger list includes broad phrases like “代码审查” and “检查我的PR”, which can overlap with ordinary user requests and cause the skill to activate in situations the user did not clearly intend. Because this skill performs multi-step actions including external GitHub operations, ambiguous activation increases the risk of unintended review workflows and downstream side effects.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The usage examples define ambiguous activation boundaries by allowing generic requests such as “检查我的PR” without requiring a precise target or explicit consent for the full workflow. In context, this is more dangerous because the workflow chains multiple skills and may initiate repository inspection, issue creation, and local logging from a casual request.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs automatic creation of GitHub Issues for each discovered problem but does not prominently warn users that it may modify remote repository state. This can lead to unintended spam, disclosure of internal review findings to collaborators, or unauthorized actions if the operator did not realize the workflow would create artifacts on GitHub.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
78% confidence
Finding

The manifest presents the skill description, category, triggers, and step names primarily in Chinese, with only limited English trigger coverage, and does not state that the language is configurable or region-specific. This can violate language/locale choice expectations when users are not given an explicit opt-in or alternative locale.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger phrase set includes broad, common requests such as '审查PR', '代码审查', and 'review PR', which can overlap with ordinary user intent and cause the workflow to activate unexpectedly. Because this workflow performs downstream actions including issue creation and logging, accidental activation can lead to unintended external side effects rather than a harmless suggestion.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This trigger is broad enough to match routine PR discussion, increasing the chance of unintended execution during everyday collaboration. In this workflow, accidental activation is more dangerous because it can cascade into repository analysis, external issue creation, and persistence of review-derived data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The workflow sends findings and PR context to a 'self-improvement' step that records novel patterns into a learning file, yet it does not disclose this persistence behavior. That can result in retention of project-specific or sensitive review context beyond the immediate task, which is more concerning in a code-review pipeline handling repository metadata and issue counts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The README presents the skill name, instructions, examples, and outputs entirely in Chinese, including the sample AI responses, with no indication that other languages are supported or that Chinese is required for a specific regional or compliance reason. That creates a natural-language locale constraint without user opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The note that self-improvement logs are stored in .learnings/ discloses persistent local storage, but the skill does not warn users up front that review-derived data may be retained. This is risky because PR contents, security findings, or repository metadata could be written to disk and persist beyond the session, creating privacy and data-handling concerns.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.