Back to skill

Security audit

repo runner

Security checks for vulnerabilities and agentic risk

Overview

This skill is meant to run untrusted GitHub projects locally, which is disclosed, but its instructions rely on repository docs for commands without enough explicit approval and isolation requirements.

Install only if you are comfortable with an agent helping run untrusted repositories locally. Review every command before execution, avoid curl|bash and similar remote execution, use an isolated container or disposable workspace without secrets, and do not expose real .env values or host credentials to projects you do not trust.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:29
Finding

Untrusted Repository Documentation Can Direct Arbitrary Command Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 29–31 and 72–74
Vulnerability Type: Untrusted instructions influencing local command execution
Risk Level: High

Vulnerable Code

md
2. Find the canonical docs
   - Prefer `README.md` + `docs/` + `CONTRIBUTING.md`
   - Extract: prerequisites (Node/Python/Docker/Go/Rust), install steps, env vars, run command(s), ports.
md
7. Run
   - Use the docs’ recommended run target (dev server, CLI, compose stack, etc.)
   - Capture logs, detect common failures, iterate

Technical Analysis

The skill treats files from an untrusted repository, including README.md, docs/, and CONTRIBUTING.md, as authoritative sources for commands that the agent should execute. An attacker controlling a repository can place malicious shell commands in those files and describe them as required installation, configuration, troubleshooting, or startup steps.

The safety rule at SKILL.md:19 requires confirmation before package-manager installation or curl | bash, but it does not establish equivalent approval requirements for other commands obtained from repository documentation. It also does not require command validation, an allowlist, sandboxing, restricted filesystem access, disabled network access, or rejection of shell operators such as pipelines and redirections.

Consequently, commands other than the specifically identified installation and curl | bash cases could be executed under the agent’s local identity. Examples include commands that delete files, read credentials, upload local data, modify shell configuration, or execute a downloaded payload through mechanisms not literally written as curl | bash.

The reference to curl | bash at SKILL.md:19 is a warning rather than an actual remote-payload execution instruction. The audited project contains no URL or remote payload. However, merely asking for confirmation would not make such a command sa ...[truncated 1793 chars]

Remediation
View remediation

Remediation Suggestions

  1. Treat repository documentation strictly as untrusted informational input, not as executable instructions.
  2. Present every proposed command to the user and require explicit approval immediately before execution, not only for dependency installation and curl | bash.
  3. Reject or require enhanced review for commands containing shell pipelines, redirections, command substitution, privilege escalation, destructive operations, encoded payloads, background execution, or access outside the project workspace.
  4. Do not execute curl | bash or equivalent remote execution patterns. Download resources separately, pin an expected version and cryptographic digest, inspect the content, and execute only in isolation if necessary.
  5. Run untrusted projects in a restricted container or sandbox with:
    • No host secrets or inherited credentials.
    • No unnecessary host filesystem mounts.
    • A read-only base filesystem where practical.
    • A dedicated unprivileged user.
    • Restricted outbound network access.
    • CPU, memory, process, and execution time limits.
  6. Maintain a narrow allowlist of routine inspection commands. Require additional approval for commands outside that allowlist.
  7. Separate command suggestion from command execution so that helper scripts and documentation parsing cannot automatically trigger generated commands.
  8. Display the command, working directory, environment changes, filesystem access, and expected network activity before requesting approval.
  9. Update the safety rules to state explicitly that repository files may contain prompt injection or malicious operational instructions and must never override the skill’s security constraints.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description says this skill bootstraps and runs a GitHub project by following its documentation, implying active setup and execution behavior. The supplied code only examines the repository contents for common files, emits metadata about detected docs and project ecosystems, and reads package.json scripts if Node is available. Its primary purpose is project detection/introspection, not running or bootstrapping. This is a material description-behavior mismatch.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 19)May include surrounding context.

md
## Safety rules (must follow)

- Treat repo code as untrusted.
- Before running `npm/pnpm/yarn install` (or any `curl | bash`), ask for confirmation.
- Never paste or store secrets. If `.env` is needed, ask user to provide values out-of-band.

## Workflow

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/suggest_node_commands.sh (reported line 60)May include surrounding context.

sh
echo "run=${run_prefix} <script>  # (no obvious dev/start script)"
fi

if [[ -f .env.example && ! -f .env ]]; then
  echo "env_hint=.env.example exists; consider copying to .env (ask user for values)"
fi

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/suggest_node_commands.sh (reported line 61)May include surrounding context.

sh
echo "run=${run_prefix} <script>  # (no obvious dev/start script)"
fi

if [[ -f .env.example && ! -f .env ]]; then
  echo "env_hint=.env.example exists; consider copying to .env (ask user for values)"
fi

Static analysis

No suspicious patterns detected.