Back to skill

Security audit

GitHub Accelerator

Security checks for vulnerabilities and agentic risk

Overview

This GitHub mirror helper is mostly purpose-aligned, but it includes unsafe clone/download behavior and under-scoped repository write guidance that users should review before installing.

Install only if you are comfortable with a shell-based GitHub mirror helper that contacts public proxy services. Use it only for public GitHub content, verify checksums or signed tags before using downloaded code, avoid token-bearing or private URLs, do not run clone into an existing directory, and require explicit approval before any repository write or API ref update flow.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/gh_accel.sh:153
Finding

Failed clone attempts can recursively delete pre-existing directories

Content
View full analysis
$dir" return 0 fi rm -rf "$dir" echo " ✗ 直连失败,降级镜像…" fi for base in "${CLONE_PROXIES[@]}"; do echo "→ 镜像: $base/$repo" if git clone "$base/$repo" "$dir"; then echo "✅ 经镜像 clone 成功 -> $dir" echo "⚠️ remote 指向镜像,push 前执行:" echo " git -C $dir remote set-url origin https://github.com/$repo.git" return 0 fi rm -rf "$dir" echo " ✗ 失败" done ``` ### Technical Analysis The clone destination is derived from the user-supplied `dir` argument. After every failed `git clone`, the script executes `rm -rf "$dir"` without establishing that the directory was created by the current invocation. If the destination already exists, `git clone` ordinarily fails because the destination is nonempty. The subsequent cleanup then recursively removes that pre-existing directory. Quoting prevents shell argument injection, but it does not make deletion of an attacker-selected path safe. The implementation has no checks for: - A destination that existed before the command started. - Root, home, current-working-directory, or parent-directory targets. - Symbolic-link or path-resolution concerns. - Whether the current process created the directory. - Whether the failed clone wrote anything into the destination. ### Attack Path 1. An attacker persuades the user or Agent to invoke the Skill with an existing writable directory as the clone destination. 2. For example: ```bash scripts/gh_accel.sh clone OWNER/REPO /home/user/important-project ``` 3. `git clone` fails because the destination already exists and is nonempty. 4. The script executes: ```bash rm -rf "/home/user/i ...[truncated 683 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/gh_accel.sh:124
Finding

Arbitrary URLs can be fetched directly and disclosed to public proxy services

Content
View full analysis
$out ($(du -h "$out" | cut -f1))" return 0 fi echo " ✗ 直连失败 (http=$code),降级镜像…" fi for p in "${DL_PROXIES[@]}"; do echo "→ 镜像: $p" code=$(fetch "$p/$url" "$out" 90) if [ "$code" = "200" ] && [ -s "$out" ]; then echo "✅ 经 $p 下载成功 -> $out ($(du -h "$out" | cut -f1))" return 0 fi echo " ✗ $p 失败 (http=$code)" done ``` ### Technical Analysis The command is documented as a GitHub downloader, but the implementation accepts any value beginning with `http`. It does not parse the URL or enforce an allowlist of GitHub-controlled hosts. Consequently, an attacker-controlled invocation can make the Agent environment issue HTTP requests to arbitrary destinations. Depending on the environment, this may include loopback services, private network services, cloud metadata endpoints, and other HTTP resources not externally reachable. If direct retrieval fails or `--no-direct` is used, the complete original URL is appended to every configured download proxy. Query strings are retained. Sensitive signed URLs, access parameters, internal hostnames, and resource paths can therefore be disclosed to `ghfast.top`, `gh-proxy.com`, or locally configured proxy operators. The weak prefix test also accepts unexpected values such as non-HTTPS URLs. It does not reject URL credentials, private IP address ranges, redirects to private destinations, or se ...[truncated 1296 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/gh_accel.sh:126
Finding

Downloads can overwrite existing files before success is established

Content
View full analysis
$out ($(du -h "$out" | cut -f1))" return 0 fi echo " ✗ 直连失败 (http=$code),降级镜像…" fi for p in "${DL_PROXIES[@]}"; do echo "→ 镜像: $p" code=$(fetch "$p/$url" "$out" 90) if [ "$code" = "200" ] && [ -s "$out" ]; then echo "✅ 经 $p 下载成功 -> $out ($(du -h "$out" | cut -f1))" return 0 fi ``` The called helper writes directly to that path: ```bash fetch() { local code rc code=$(curl -sL --max-time "$3" -o "$2" -w '%{http_code}' "$1" 2>/dev/null) rc=$? [ $rc -ne 0 ] && code=000 echo "${code:-000}" } ``` ### Technical Analysis The output filename is automatically derived from the final URL path component and placed in the current working directory. The script does not test whether that path already exists and does not require explicit overwrite approval. `curl -o` writes directly to the selected path. An existing file can therefore be truncated or replaced before the script knows whether the download succeeded. Failed direct and proxy attempts reuse the same output path, so an unsuccessful operation can still destroy pre-existing content or leave a partial file behind. Because the filename is attacker-influenced through the URL basename, an attacker can select a name matching a valuable file in the Agent's current directory. Although `basename` limits direct directory traversal through this particular variable, it does not prevent collisions with existing local files. ### Attack ...[truncated 1138 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/gh_accel.sh:137
Finding

Artifacts from public mirrors are accepted without integrity verification

Content
View full analysis
$out ($(du -h "$out" | cut -f1))" return 0 fi echo " ✗ $p 失败 (http=$code)" done ``` ### Technical Analysis The script treats an HTTP 200 response and a nonempty file as sufficient proof of a successful download from a public mirror. It does not verify: - A cryptographic checksum. - A publisher signature or attestation. - Expected file size. - Expected content type or format. - Equivalence with the official GitHub artifact. - The identity or trust state of the mirror. The documentation advises users to compare sizes or SHA-256 hashes manually, but the implementation reports success before any such verification. Automated consumers may therefore treat an untrusted mirror response as an authentic GitHub artifact. This is particularly dangerous for executable releases, shell scripts, source archives, package files, and build dependencies. A compromised or malicious mirror can return modified content while preserving a successful HTTP status. ### Attack Path 1. Direct GitHub retrieval fails or the caller uses `--no-direct`. 2. The script sends the artifact URL through a configured public mirror. 3. The mirror is compromised, malicious, subject to DNS manipulation, or serves stale or substituted content. 4. The mirror returns an attacker-controlled, nonempty response with HTTP status 200. 5. The script records the file and reports the operation as successful. 6. A user, Agent, build system, or installer subsequently executes or consumes the substituted artifact. ### Impact Assessment The immediate privilege level is that of the process consuming the downloaded artifact. If the artifact ...[truncated 417 chars]
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (9)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This section explicitly instructs an API-based sequence that is equivalent to git push, including creating blobs, trees, commits, and updating refs. That is a write-capable repository modification flow materially beyond a 'fallback mirrors for git' skill, and it could be misused to alter repository history or bypass expected review of write operations if an agent follows it automatically.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README actively instructs users to route GitHub downloads and clones through third-party mirror/proxy services, but it does not clearly warn that those services can observe requested repository URLs, client IPs, timing, and potentially alter downloaded content if not independently verified. In this skill's context, that omission matters because the feature is specifically designed to redirect trust from GitHub to transient mirrors whose reliability and operator trustworthiness are uncertain.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill clearly instructs shell execution and network access (bash, curl, git, gh api) but does not declare any tool scope or permission boundaries. This creates an authorization ambiguity where an agent may invoke powerful capabilities without an explicit least-privilege contract, increasing the chance of unsafe execution or policy bypass in environments that rely on metadata for enforcement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file contains user-facing instructions almost exclusively in Chinese, but does not state that the skill is Chinese-only or provide an opt-in language/locale choice. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document claims mirrors are read-only and implies push should return to the official source, but later introduces an API-based push-equivalent write path. This inconsistency is dangerous because agents or users may infer the skill is safely read-only while it actually documents repository mutation workflows, undermining trust boundaries and change-control expectations.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill is presented as a GitHub mirror fallback for read-oriented recovery, but these instructions broaden behavior into GitHub API repository access beyond simple mirroring. Even if the read examples are legitimate, the mismatch between declared purpose and operational scope can cause an agent to overreach and use authenticated API access in contexts where only transport fallback was expected.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The stated purpose is to provide fallback mirrors for GitHub/git access. Instructing the agent to persistently modify ~/.config/gh-accelerator/proxies.conf is a local state-changing capability that goes beyond simply using mirrors, especially since the manifest does not declare configuration management as part of the skill's scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script's help text, comments, status messages, and warnings are all presented in Chinese, and there is no option to select another language or locale. This can violate a language/locale policy when skills are expected to avoid forcing a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

All user-facing instructional text in this template is written in Chinese, and there is no indication that users may choose another language or locale. Under the stated policy, a skill should not force a specific language without user opt-in unless the constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.