Back to skill

Security audit

GitHub开发工具

Security checks for vulnerabilities and agentic risk

Overview

This GitHub CLI skill appears purpose-aligned but needs review because it can drive persistent GitHub changes without clear user confirmation or tight scoping.

Install only if you are comfortable letting the agent use your GitHub CLI authentication. Before any write/admin action, confirm the target repository, exact command, and expected side effects; prefer restricted GitHub tokens and read-only gh operations when possible.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill is advertised for very broad scenarios like code generation, programming assistance, debugging, testing, and deployment, which makes it likely to activate in many generic development contexts. Because the skill includes exec capability and can operate on GitHub state, overbroad triggering increases the chance an agent invokes it unnecessarily or with insufficient user intent validation, leading to risky actions in the wrong context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The markdown describes operational flows and outputs but does not prominently warn that actions may modify remote GitHub state, including creating issues, PRs, runs, API-side changes, or webhooks. In an agent setting, the absence of a clear destructive-action warning can cause users or orchestrators to treat the skill as informational, increasing the risk of accidental external changes.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill claims that only whitelisted commands are executed and that user input is not concatenated, but the document elsewhere encourages direct use of flexible gh CLI commands such as gh api, issue/PR creation, and webhook operations. This mismatch is dangerous because implementers or agents may trust the safety claims while still passing user-controlled arguments into powerful GitHub-mutating commands, enabling unintended repository changes, webhook creation, or data access.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.