Back to skill

Security audit

mihomo Proxy Manager

Security checks for vulnerabilities and agentic risk

Overview

This proxy-management skill is related to its stated purpose, but installation and defaults create high-impact review concerns around persistent privileged services, mutable downloads, and exposed proxy-management data.

Review before installing. Use a pinned, trusted package version; verify the mihomo binary before execution; avoid pasting sensitive subscription URLs into logged agent sessions; change the controller to loopback with a secret; inspect any created systemd or launchd service; and be prepared to remove service files manually if you uninstall.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Findings (7)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
src/install.js:108
Finding

Root systemd service executes a user-writable binary

Content
View full analysis
Remediation
View remediation

T06 · System Persistence

Error
Location
src/install.js:130
Finding

Installation automatically creates cross-session persistence

Content
View full analysis
Labelcom.mihomo.daemon ProgramArguments ${binPath} -d ${configDir} RunAtLoad KeepAlive `; const agentsDir = join(homedir(), 'Library', 'LaunchAgents'); mkdirSync(agentsDir, { recursive: true }); const plistPath = join(agentsDir, 'com.mihomo.daemon.plist'); writeFileSync(plistPath, plist); return true; } catch { return false; } } ``` ### Technical Analysis The general-purpose `install` operation does more than download a binary. On Linux, it enables a systemd or user systemd service. On macOS, it creates a LaunchAgent with both `RunAtLoad` and `KeepAlive` enabled. These changes survive the current process and user session. The documentation describes installation primarily as downloading and installing Mihomo and does not clearly disclose that the command also registers persistent startup components. There is also no corresponding uninstall command that reliably disables and removes these services. ### Attack Path 1. An agent or user follows the documented `npx mihomod install` instruction. 2. The installer writes a syst ...[truncated 631 chars]
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
src/install.js:10
Finding

Downloaded release binary is executed without cryptographic integrity verification

Content
View full analysis
1024) { throw new Error(`Download size mismatch: expected ~${asset.size}, got ${downloadedSize}`); } ``` ```js // src/install.js:89-97 try { const result = spawnSync(binPath, ['-v'], { encoding: 'utf8', stdio: ['pipe', 'pipe', 'pipe'] }); const ver = (result.stdout || '').trim(); log(`Installed: ${ver}`); return { installed: true, version: ver, path: binPath, configDir, service: serviceInstalled }; } catch { return { installed: true, version, path: binPath, configDir, service: serviceInstalled }; } ``` ### Technical Analysis The installer dynamically selects the latest GitHub release, downloads an executable archive, extracts it, and runs the resulting binary. Its only integrity check compares the downloaded size with the size in release metadata obtained from the same upstream source. File size is not a cr ...[truncated 1084 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
src/configure.js:10
Finding

Generated configuration exposes the Mihomo controller on all interfaces without authentication

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
src/configure.js:178
Finding

Subscription credentials are exposed through verbatim URL logging

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
src/configure.js:139
Finding

Credential-bearing configuration files are created without explicit restrictive permissions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
src/subscribe.js:218
Finding

Unrestricted subscription URL fetching enables server-side request forgery

Content
View full analysis
0) { return { format: 'clash', raw: text, config: parsed }; } } catch {} const trimmed = text.trim(); // Try base64 encoded list try { const decoded = decodeBase64(trimmed); const lines = decoded .split('\n') .map(line => line.trim()) .filter(line => line.match(/^(vmess|ss|trojan|vless):\/\//)); if (lines.length > 0) { const proxies = lines.map(line => parseProxyUrl(line)); return { format: 'base64', proxies }; } } catch {} // Try line-by-line URLs const lines = text .split('\n') .map(line => line.trim()) .filter(line => line.match(/^(vmess|ss|trojan|vless):\/\//)); if (lines.length) { const proxies = lines.map(line => parseProxyUrl(line)); return { format: 'urls', proxies }; } throw new Error('Unable to parse subscription format'); } ``` ```js // src/configure.js:178-184 export async function configure(subscriptionUrl, config) { const configDir = getConfigDir(); const configPath = config?.mihomo?.configPath || join(configDir, 'config.yaml'); log(`Fetching subscription: ${subscriptionUrl}`); const sub = await fetchSubscription(subscriptionUrl); ``` ### Technical Analysis The subscription URL is passed directly to `fetch()` without validating ...[truncated 1749 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (48)

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

The code clearly performs installation of the mihomo executable and config directory setup, which is consistent with part of 'manage mihomo proxy' and specifically the 'install' aspect. However, it also installs and enables background services using systemd or launchd, including attempting to write to /etc/systemd/system via sudo, which is a significant system-modifying capability not reflected in the declared permissions (none declared). More importantly, the declared description promises configuration from subscriptions, health monitoring, and automatic node switching, but this code chunk contains none of that logic. Since the evaluation asks whether the declared description accurately represents what the supplied code chunk actually does, this is a mismatch: the chunk is narrower in some promised features and includes impactful persistence/service-installation behavior not explicitly declared.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The description presents a broad proxy-management skill covering installation, subscription-based configuration, health monitoring, and automatic node switching. This code chunk instead focuses narrowly on starting and stopping the mihomo service across Linux and macOS, including use of sudo/systemctl, launchctl, detached process spawning, PID file persistence, and pkill fallback. While service management is related to 'manage mihomo proxy,' the actual behavior is materially narrower than the declared feature set, and it also exercises explicit OS-level process/service control that is not reflected in the empty declared permissions. Therefore the description does not accurately represent this code chunk's actual behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README promotes generating configuration from subscription URLs but does not warn that these URLs often embed provider credentials, tokens, or personally identifying subscription data and require transmission to external services. In a proxy-management skill, that omission is more dangerous because users may paste sensitive links into agent workflows, logs, shells, or remote environments without realizing the exposure.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The README instructs users to run npx mihomod without pinning a package version, which causes execution of whatever version is current in the npm registry at runtime. If the package is updated maliciously, compromised, or a typo/namespace confusion issue occurs, users and agents may execute unreviewed code on their systems.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

This command example uses npx mihomod without a pinned version, so execution depends on the latest package published at the time the command is run. For an agent-friendly tool that performs networking and configuration changes, that increases supply-chain risk and can lead to arbitrary code execution under the user's account.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The unpinned npx mihomod invocation means the README directs users to execute a package version that may change over time without notice. Because this tool ingests remote proxy links and manages local proxy configuration, a compromised release could abuse network access, exfiltrate secrets, or alter system state.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

Running npx mihomod start without a pinned version exposes users to npm supply-chain drift, where the executed code is not necessarily the code the README author validated. Since the command starts a network proxy service, a malicious update could create persistence, modify traffic routing, or expose local services.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

This README example invokes npx mihomod status without constraining the version, so users may execute newly published code they have not audited. In an automation context, that can silently convert a harmless status check into arbitrary code execution via a compromised package release.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The npx mihomod watch example is unpinned, which is especially risky because it starts a long-running watchdog process fetched dynamically from npm. If a malicious or compromised release is published, the process could maintain ongoing access, manipulate traffic failover, or exfiltrate network metadata.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill declares network- and environment-dependent behavior but does not define any explicit tool scope or permission boundaries. That increases the chance an agent will invoke networked installation/configuration actions with broader capabilities than intended, reducing reviewability and allowing risky side effects such as downloading code or altering host proxy settings.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

Using npx mihomod install without a pinned version causes execution of whatever package version the registry serves at runtime. This creates a supply-chain risk: a compromised maintainer account, typo-squatted package, or malicious update could lead to arbitrary code execution on the user's machine during install.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The unpinned npx mihomod invocation allows execution of an untrusted latest package version from the npm registry. Because this command performs installation-related actions, a malicious or compromised package update could execute arbitrary code and modify the system.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

This command fetches and executes an unpinned package version while also accepting a remote subscription URL as input. The combination of network-fetched code and network-fetched configuration materially raises supply-chain and remote-content risk, especially for a tool that writes proxy configuration.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

Executing npx mihomod add without pinning the package version exposes users to arbitrary code execution from an unexpected package update. Since the skill processes opaque proxy URIs, the command may be used frequently on untrusted inputs, making the runtime package trust issue more consequential.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The command relies on an unpinned npx package, meaning registry state controls what code is executed. Because this tool affects local proxy configuration, malicious package behavior could persistently reroute traffic or exfiltrate data.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

An unpinned npx invocation for proxy-node addition is a supply-chain execution risk. If the package is replaced or trojanized, the attacker gains a path to change network routing or run arbitrary host commands under the user's context.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The skill instructs users to execute an unpinned package from npm for security-sensitive proxy configuration. In this context, compromise could directly affect confidentiality and integrity of network traffic by installing malicious hooks, altering configs, or executing arbitrary code.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

Starting the service through unpinned npx means the executable logic is resolved dynamically from the registry. That is unsafe for a command that launches long-running proxy-related processes and could establish persistence or manipulate traffic if compromised.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

Even for stop operations, unpinned npx causes arbitrary package code to run before performing the requested action. A malicious update could ignore the requested stop behavior and instead execute unrelated payloads or modify system state.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The status command still executes code from an unpinned npm package, which is risky because even read-only-seeming commands can run arbitrary logic. This unnecessarily exposes users to supply-chain compromise during routine monitoring.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

Listing nodes with an unpinned npx package retains the same arbitrary-code-execution risk as more obviously privileged commands. Frequent low-friction commands like this can normalize insecure execution patterns and widen exposure windows.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

Auto-switching via an unpinned npm package gives remote registry state influence over traffic-routing decisions and local process behavior. In a proxy-management context, that can enable traffic interception, covert routing changes, or arbitrary code execution.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

Using an unpinned npx package for switching to a named node is especially sensitive because it directly changes network paths. A malicious package version could silently route traffic through attacker-controlled infrastructure or alter additional system settings.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

Running a long-lived watchdog from an unpinned npm package compounds supply-chain risk by granting ongoing execution over monitoring and auto-switching behavior. If compromised, it could maintain persistence, manipulate proxy selection over time, and continuously affect network confidentiality.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · src/install.js (reported line 10)May include surrounding context.

js
import { log } from './logger.js';
import { homedir } from 'os';

const RELEASES_API = 'https://api.github.com/repos/MetaCubeX/mihomo/releases/latest';
const DOWNLOAD_TIMEOUT_MS = 120000;

async function getLatestRelease() {

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/configure.js:132

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/install.js:65

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/platform.js:39

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/service.js:40