T05 · Unauthorized Access and Privilege Escalation
- Location
src/install.js:108- Finding
Root systemd service executes a user-writable binary
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This proxy-management skill is related to its stated purpose, but installation and defaults create high-impact review concerns around persistent privileged services, mutable downloads, and exposed proxy-management data.
Review before installing. Use a pinned, trusted package version; verify the mihomo binary before execution; avoid pasting sensitive subscription URLs into logged agent sessions; change the controller to loopback with a secret; inspect any created systemd or launchd service; and be prepared to remove service files manually if you uninstall.
src/install.js:108Root systemd service executes a user-writable binary
src/install.js:130Installation automatically creates cross-session persistence
src/install.js:10Downloaded release binary is executed without cryptographic integrity verification
src/configure.js:10Generated configuration exposes the Mihomo controller on all interfaces without authentication
src/configure.js:178Subscription credentials are exposed through verbatim URL logging
src/configure.js:139Credential-bearing configuration files are created without explicit restrictive permissions
src/subscribe.js:218Unrestricted subscription URL fetching enables server-side request forgery
The code clearly performs installation of the mihomo executable and config directory setup, which is consistent with part of 'manage mihomo proxy' and specifically the 'install' aspect. However, it also installs and enables background services using systemd or launchd, including attempting to write to /etc/systemd/system via sudo, which is a significant system-modifying capability not reflected in the declared permissions (none declared). More importantly, the declared description promises configuration from subscriptions, health monitoring, and automatic node switching, but this code chunk contains none of that logic. Since the evaluation asks whether the declared description accurately represents what the supplied code chunk actually does, this is a mismatch: the chunk is narrower in some promised features and includes impactful persistence/service-installation behavior not explicitly declared.
The description presents a broad proxy-management skill covering installation, subscription-based configuration, health monitoring, and automatic node switching. This code chunk instead focuses narrowly on starting and stopping the mihomo service across Linux and macOS, including use of sudo/systemctl, launchctl, detached process spawning, PID file persistence, and pkill fallback. While service management is related to 'manage mihomo proxy,' the actual behavior is materially narrower than the declared feature set, and it also exercises explicit OS-level process/service control that is not reflected in the empty declared permissions. Therefore the description does not accurately represent this code chunk's actual behavior.
The README promotes generating configuration from subscription URLs but does not warn that these URLs often embed provider credentials, tokens, or personally identifying subscription data and require transmission to external services. In a proxy-management skill, that omission is more dangerous because users may paste sensitive links into agent workflows, logs, shells, or remote environments without realizing the exposure.
The README instructs users to run npx mihomod without pinning a package version, which causes execution of whatever version is current in the npm registry at runtime. If the package is updated maliciously, compromised, or a typo/namespace confusion issue occurs, users and agents may execute unreviewed code on their systems.
This command example uses npx mihomod without a pinned version, so execution depends on the latest package published at the time the command is run. For an agent-friendly tool that performs networking and configuration changes, that increases supply-chain risk and can lead to arbitrary code execution under the user's account.
The unpinned npx mihomod invocation means the README directs users to execute a package version that may change over time without notice. Because this tool ingests remote proxy links and manages local proxy configuration, a compromised release could abuse network access, exfiltrate secrets, or alter system state.
Running npx mihomod start without a pinned version exposes users to npm supply-chain drift, where the executed code is not necessarily the code the README author validated. Since the command starts a network proxy service, a malicious update could create persistence, modify traffic routing, or expose local services.
This README example invokes npx mihomod status without constraining the version, so users may execute newly published code they have not audited. In an automation context, that can silently convert a harmless status check into arbitrary code execution via a compromised package release.
The npx mihomod watch example is unpinned, which is especially risky because it starts a long-running watchdog process fetched dynamically from npm. If a malicious or compromised release is published, the process could maintain ongoing access, manipulate traffic failover, or exfiltrate network metadata.
The skill declares network- and environment-dependent behavior but does not define any explicit tool scope or permission boundaries. That increases the chance an agent will invoke networked installation/configuration actions with broader capabilities than intended, reducing reviewability and allowing risky side effects such as downloading code or altering host proxy settings.
Using npx mihomod install without a pinned version causes execution of whatever package version the registry serves at runtime. This creates a supply-chain risk: a compromised maintainer account, typo-squatted package, or malicious update could lead to arbitrary code execution on the user's machine during install.
The unpinned npx mihomod invocation allows execution of an untrusted latest package version from the npm registry. Because this command performs installation-related actions, a malicious or compromised package update could execute arbitrary code and modify the system.
This command fetches and executes an unpinned package version while also accepting a remote subscription URL as input. The combination of network-fetched code and network-fetched configuration materially raises supply-chain and remote-content risk, especially for a tool that writes proxy configuration.
Executing npx mihomod add without pinning the package version exposes users to arbitrary code execution from an unexpected package update. Since the skill processes opaque proxy URIs, the command may be used frequently on untrusted inputs, making the runtime package trust issue more consequential.
The command relies on an unpinned npx package, meaning registry state controls what code is executed. Because this tool affects local proxy configuration, malicious package behavior could persistently reroute traffic or exfiltrate data.
An unpinned npx invocation for proxy-node addition is a supply-chain execution risk. If the package is replaced or trojanized, the attacker gains a path to change network routing or run arbitrary host commands under the user's context.
The skill instructs users to execute an unpinned package from npm for security-sensitive proxy configuration. In this context, compromise could directly affect confidentiality and integrity of network traffic by installing malicious hooks, altering configs, or executing arbitrary code.
Starting the service through unpinned npx means the executable logic is resolved dynamically from the registry. That is unsafe for a command that launches long-running proxy-related processes and could establish persistence or manipulate traffic if compromised.
Even for stop operations, unpinned npx causes arbitrary package code to run before performing the requested action. A malicious update could ignore the requested stop behavior and instead execute unrelated payloads or modify system state.
The status command still executes code from an unpinned npm package, which is risky because even read-only-seeming commands can run arbitrary logic. This unnecessarily exposes users to supply-chain compromise during routine monitoring.
Listing nodes with an unpinned npx package retains the same arbitrary-code-execution risk as more obviously privileged commands. Frequent low-friction commands like this can normalize insecure execution patterns and widen exposure windows.
Auto-switching via an unpinned npm package gives remote registry state influence over traffic-routing decisions and local process behavior. In a proxy-management context, that can enable traffic interception, covert routing changes, or arbitrary code execution.
Using an unpinned npx package for switching to a named node is especially sensitive because it directly changes network paths. A malicious package version could silently route traffic through attacker-controlled infrastructure or alter additional system settings.
Running a long-lived watchdog from an unpinned npm package compounds supply-chain risk by granting ongoing execution over monitoring and auto-switching behavior. If compromised, it could maintain persistence, manipulate proxy selection over time, and continuously affect network confidentiality.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
import { log } from './logger.js';
import { homedir } from 'os';
const RELEASES_API = 'https://api.github.com/repos/MetaCubeX/mihomo/releases/latest';
const DOWNLOAD_TIMEOUT_MS = 120000;
async function getLatestRelease() {
Detected: suspicious.dangerous_exec