Back to skill

Security audit

github

Security checks for vulnerabilities and agentic risk

Overview

This GitHub workflow skill is mostly coherent, but it handles the user's GitHub token in a way that can expose it through local process arguments.

Review the skill before installing if it will be used with private repositories or write-capable GitHub credentials. Prefer revising the attachment-download command to avoid putting tokens in process arguments, and confirm PR creation, issue-closing keywords, reviewers, and auto-merge settings each time they could change repository state.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:46
Finding

GitHub Authentication Token Exposed Through Process Arguments

Content
View full analysis
/imgN.png ``` ### Technical Analysis The command substitutes the output of `gh auth token` directly into a `curl` command-line argument. After shell expansion, the complete GitHub token becomes part of the running process's argument vector as an HTTP `Authorization` header. Depending on the host configuration, command-line arguments may be observable through process inspection interfaces, monitoring agents, diagnostic tooling, audit logs, or process-listing utilities. A local user or compromised process with sufficient visibility could capture the token while `curl` is running. Authentication is legitimately required to download attachments from private GitHub repositories. However, placing the credential in process arguments exceeds the minimum necessary exposure for that operation. The use of `curl -L` also permits redirects, so redirect behavior and destination hosts should be restricted even when the client is expected to suppress credentials across host boundaries. ### Attack Path 1. A user asks the agent to read an issue containing an authenticated private-repository attachment. 2. The Skill runs the documented command and invokes `gh auth token`. 3. The shell expands the token into the `curl` argument containing the `Authorization` header. 4. While `curl` is active, a local attacker, compromised monitoring component, or other process with permission to inspect process arguments captures the expanded header. 5. The attacker extracts the bearer token and submits authenticated requests to GitHub. 6. The attacker gains access up to the permissions and repository scope granted to that token, until it expires or is revoked. This path requires local process visibility or access to tool ...[truncated 832 chars]
Remediation
View remediation
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Session Persistence

Medium
Category
Rogue Agent
Confidence
82% confidence
Finding

The skill reads and offers to write persistent configuration in .claude/github.json (or ~/.claude/github.json) containing operational defaults that affect future PR creation, reviewer assignment, linking behavior, and auto-merge. Persisting these settings across sessions can silently influence later state-changing actions, especially if the file is modified unexpectedly or created from a one-time conversational prompt without clear user review.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: github
description: Work with GitHub issues and pull requests via the gh CLI — query assigned/milestone issues (incl. cross-repo search and Projects v2 boards), read an issue's description AND download+view its embedded screenshots, publish branches, and create PRs with configured house defaults (reviewers, auto-merge, issue linked via closing keyword, one PR per repo). Reads reviewer/branch/title settings from `.claude/github.json` and offers to create it on first use. Use this skill whenever the user says "pull my issues", "what's assigned to me", "read issue 123", "get the screenshots from the issue", "link the PR to the issue", "enable auto-merge", or mentions "gh", "github issues", "github project board" — even if they don't explicitly say "github skill". For "create a PR" defer to the create-pr skill (this skill is its GitHub backend and supplies the PR mechanics). Do not use for Azure DevOps orgs (use the azure-devops skill) or for local git-only operations.
---

# GitHub

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description contains very broad activation cues such as matching on generic mentions of "gh", "github issues", and "github project board". That can cause the skill to activate in contexts broader than the user's actual intent, increasing the chance of invoking workflows that read repository data or prepare state-changing GitHub actions when the user only meant to discuss GitHub generally.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.