Repo Security Review
Perform security audits on GitHub repositories to identify data exfiltration, malicious code, or suspicious behavior before installation.
Workflow
1. Gather Repository Info
- Fetch the main page to understand what the project does
- Locate the GitHub repository URL
- Identify install scripts (install.sh, setup.py, Makefile, etc.)
2. Review Install Scripts
Fetch and analyze all install scripts for:
- URLs contacted - Should only be official sources (GitHub releases, package registries)
- Commands executed - Look for curl/wget to unknown hosts, eval of remote code
- File system access - Unexpected writes outside install directory
- Environment variables - Harvesting of secrets, API keys, credentials
3. Audit Source Code
Examine main application code for:
- Network calls - All HTTP/HTTPS requests and their destinations
- Data collection - Any telemetry, analytics, or phone-home behavior
- File access - Reading sensitive files (~/.ssh, ~/.aws, credentials)
- Obfuscated code - Base64 encoded strings, eval(), exec()
4. Check Dependencies
Review dependency files (package.json, go.mod, requirements.txt, Cargo.toml):
- Look for analytics/telemetry packages
- Check for typosquatted package names
- Verify packages are from reputable sources
5. Provide Assessment
Summarize findings with:
- Overall verdict (Safe / Caution / Unsafe)
- Network activity - All external endpoints contacted
- Data storage - Where data is stored (local vs remote)
- Red flags found - Any suspicious patterns
- Recommendation - Install as-is, build from source, or avoid
Red Flags Reference
See references/red-flags.md for comprehensive list of suspicious patterns.
Key Suspicious Patterns (Quick Reference)
Install scripts:
curl | bash from non-official URLs
- Hidden file creation (dotfiles outside expected locations)
- Modification of shell profiles to inject code
- Download and execute without verification
Source code:
- Hardcoded IPs or non-GitHub/official URLs
- Base64 encoded payloads
- Reading SSH keys, AWS credentials, browser data
- Sending data to analytics endpoints
- Obfuscated variable names
Dependencies:
analytics, telemetry, tracking packages
- Misspelled package names (typosquatting)
- Packages with very few downloads/stars
- Dependencies from personal GitHub repos
Output Format
## Security Review Summary: [Project Name]
### [Status Emoji] Install Script - [CLEAN/SUSPICIOUS/DANGEROUS]
[Findings]
### [Status Emoji] Application Code - [CLEAN/SUSPICIOUS/DANGEROUS]
[Findings]
### [Status Emoji] Dependencies - [CLEAN/SUSPICIOUS/DANGEROUS]
[Findings]
### Assessment
[Overall verdict and recommendation]
Use checkmarks for clean, warning signs for suspicious, X for dangerous.
1---2name: repo-security-review3description: Security audit for GitHub repositories before installation. Use when user wants to check if a repo/app is safe to install, review install scripts for malicious code, verify an open source project isn't collecting data, or audit dependencies for suspicious packages. Triggers on phrases like "is this safe to install", "check this repo", "review this script", "audit this code", "is this sketchy".4---5
6# Repo Security Review
7
8Perform security audits on GitHub repositories to identify data exfiltration, malicious code, or suspicious behavior before installation.
9
10## Workflow
11
12### 1. Gather Repository Info
13- Fetch the main page to understand what the project does
14- Locate the GitHub repository URL
15- Identify install scripts (install.sh, setup.py, Makefile, etc.)
16
17### 2. Review Install Scripts
18Fetch and analyze all install scripts for:
19- **URLs contacted** - Should only be official sources (GitHub releases, package registries)
20- **Commands executed** - Look for curl/wget to unknown hosts, eval of remote code
21- **File system access** - Unexpected writes outside install directory
22- **Environment variables** - Harvesting of secrets, API keys, credentials
23
24### 3. Audit Source Code
25Examine main application code for:
26- **Network calls** - All HTTP/HTTPS requests and their destinations
27- **Data collection** - Any telemetry, analytics, or phone-home behavior
28- **File access** - Reading sensitive files (~/.ssh, ~/.aws, credentials)
29- **Obfuscated code** - Base64 encoded strings, eval(), exec()
30
31### 4. Check Dependencies
32Review dependency files (package.json, go.mod, requirements.txt, Cargo.toml):
33- Look for analytics/telemetry packages
34- Check for typosquatted package names
35- Verify packages are from reputable sources
36
37### 5. Provide Assessment
38Summarize findings with:
39- **Overall verdict** (Safe / Caution / Unsafe)
40- **Network activity** - All external endpoints contacted
41- **Data storage** - Where data is stored (local vs remote)
42- **Red flags found** - Any suspicious patterns
43- **Recommendation** - Install as-is, build from source, or avoid
44
45## Red Flags Reference
46
47See [references/red-flags.md](references/red-flags.md) for comprehensive list of suspicious patterns.
48
49## Key Suspicious Patterns (Quick Reference)
50
51**Install scripts:**
52- `curl | bash` from non-official URLs
53- Hidden file creation (dotfiles outside expected locations)
54- Modification of shell profiles to inject code
55- Download and execute without verification
56
57**Source code:**
58- Hardcoded IPs or non-GitHub/official URLs
59- Base64 encoded payloads
60- Reading SSH keys, AWS credentials, browser data
61- Sending data to analytics endpoints
62- Obfuscated variable names
63
64**Dependencies:**
65- `analytics`, `telemetry`, `tracking` packages
66- Misspelled package names (typosquatting)
67- Packages with very few downloads/stars
68- Dependencies from personal GitHub repos
69
70## Output Format
71
72```
73## Security Review Summary: [Project Name]
74
75### [Status Emoji] Install Script - [CLEAN/SUSPICIOUS/DANGEROUS]
76[Findings]
77
78### [Status Emoji] Application Code - [CLEAN/SUSPICIOUS/DANGEROUS]
79[Findings]
80
81### [Status Emoji] Dependencies - [CLEAN/SUSPICIOUS/DANGEROUS]
82[Findings]
83
84### Assessment
85[Overall verdict and recommendation]
86```
87
88Use checkmarks for clean, warning signs for suspicious, X for dangerous.