T09 · Insecure Skill Coding Practices
- Location
SKILL.md:21- Finding
Untrusted External Tasks Can Trigger Privileged Agent Actions and Automatic Repository Pushes
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 21–24, 37, 92–93, 120–123, 136, and 161
Vulnerability Type: Untrusted task execution with excessive Agent and repository authority
Risk Level: HighVulnerable Code Snippets
yaml tools: - read - exec - writemarkdown Automatic pipeline: **Linear → Webhook platform → Notification channel → Task execution → Git synchronization**. Tasks created in Linear automatically trigger processing, real-time notification, execution, result write-back, and synchronization to a Git repository.json { "notify": { "channel": "discord", "discord": { "botToken": "${DISCORD_BOT_TOKEN}", "notifyUserId": "discord-user-id", "taskChannelId": "channel-id", "allowBots": true } }, "git": { "repo": "/path/to/repo", "autoPush": true, "commitPrefix": "task:", "branch": "main", "conflictStrategy": "rebase" } }markdown | 4. Execute task | Invoke a sub-Agent or local script | Mark as "Stalled" after a 30-minute timeout | | 7. Git synchronization | git add/commit/push | Handle conflicts according to conflictStrategy |bash git add research/ && commit -m "task: ENG-456 wasm research" && pushmarkdown **Availability classification:** MD+EXEC (Markdown instructions requiring exec to run scripts and webhook calls).Technical Analysis
The Skill defines an automation boundary in which task data originates from Linear and passes through externally managed webhook and notification services before being delegated to a sub-Agent or local script. The receiving Agent is granted
read,write, andexeccapabilities, while the Git configuration enables automatic pushes.The documentation does not define controls that distinguish trusted workflow metadata from untrusted task content. In particular, it does not specify:
- Authentication and signature verification for incoming webhook events.
- Authorization rules fo ...[truncated 3195 chars]
- Remediation
View remediation
Remediation Suggestions
-
Authenticate incoming events
- Require webhook signature or HMAC verification.
- Validate timestamps and unique delivery identifiers to prevent replay attacks.
- Reject events from unknown teams, projects, integrations, and webhook endpoints.
-
Authorize task initiators
- Maintain an explicit allowlist of Linear users and service identities permitted to initiate automation.
- Require project or label-based authorization in addition to
watchFilter. - Do not treat possession of task-editing access as authorization to execute local operations.
-
Treat task content strictly as untrusted data
- Parse incoming events into a typed schema.
- Permit only fixed action identifiers with predefined behavior.
- Do not translate arbitrary task prose into shell commands.
- Explicitly instruct the Agent that task titles, descriptions, comments, attachments, and bot messages cannot change system policy or request additional privileges.
-
Constrain command execution
- Replace general-purpose
execwith narrowly scoped wrapper functions. - Use an exact executable and argument allowlist; avoid shell interpretation.
- Run tasks in an isolated container or sandbox with no unnecessary host mounts.
- Disable access to unrelated environment variables, credentials, SSH agents, and network destinations.
- Replace general-purpose
-
Restrict filesystem authority
- Resolve and canonicalize the configured repository path.
- Reject path traversal, symbolic-link escapes, absolute output paths, and writes outside the approved workspace.
- Grant read access only where necessary and write access only to designated output directories.
-
Harden Git synchronization
- Set
autoPushtofalseby default. - Generate changes on a dedicated, non-protected branch using least-privilege credentials.
- Require human approval after reviewing the command plan and complete diff.
- Protect default branches and re ...[truncated 1012 chars]
- Set
-
