Back to skill

Security audit

HiLink LTE Modem

Security checks for vulnerabilities and agentic risk

Overview

The skill has a clear LTE modem purpose, but its helper script is risky enough that crafted inputs or a modified config file could make it run unintended commands or change modem data.

Review before installing. Use this only for a modem you control, avoid storing SIM PINs in the config file, avoid passing real PINs in command lines or agent transcripts, restrict config file permissions, and do not use SMS delete or PIN-changing commands unless you explicitly intend those changes. The package looks purpose-aligned rather than intentionally malicious, but the script should be fixed before routine use.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/hilink.sh:211
Finding

Arbitrary Python Code Injection Through the SMS Index Argument

Content
View full analysis
1501000') echo "$resp" | python3 -c " import sys, xml.etree.ElementTree as ET tree = ET.parse(sys.stdin) for msg in tree.findall('.//Message'): if msg.findtext('Index') == '${index}': print(f'From: {msg.findtext(\"Phone\")}') print(f'Date: {msg.findtext(\"Date\")}') print('---') print(msg.findtext('Content', '')) break else: print('SMS ${index} not found') " 2>/dev/null } ``` ### Technical Analysis The `index` value originates from the third command-line argument and is inserted directly into source code supplied to `python3 -c`. The shell's double-quoted string permits parameter expansion, but it does not encode the expanded value as a safe Python string. An attacker-controlled index containing quotes, line breaks, comments, or other Python syntax can terminate the intended string literal and alter the generated Python program. Because the result is interpreted as source code rather than data, successful injection allows arbitrary Python execution. The value is interpolated in two places, which may require the malicious input to preserve valid Python syntax at both locations. This complicates exploitation but does not establish a security boundary; a crafted multiline value can account for both contexts. ### Attack Path 1. An attacker supplies or persuades a user or Agent to use a crafted value as an SMS index. 2. The user invokes: ```bash s ...[truncated 1019 chars]
Remediation
View remediation
&2 return 1 } ``` 2. Pass the index as a separate Python argument: ```bash echo "$resp" | python3 -c ' import sys import xml.etree.ElementTree as ET index = sys.argv[1] tree = ET.parse(sys.stdin) for msg in tree.findall(".//Message"): if msg.findtext("Index") == index: print(f"From: {msg.findtext(\"Phone\")}") print(f"Date: {msg.findtext(\"Date\")}") print("---") print(msg.findtext("Content", "")) break else: print(f"SMS {index} not found") ' "$index" ``` 3. Never interpolate untrusted values into source strings passed to interpreters such as `python3 -c`, `sh -c`, or `eval`. 4. Add regression tests using quotes, newlines, semicolons, backslashes, and Python comment characters to verify that malformed indices are rejected and never interpreted. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/hilink.sh:161
Finding

XML Request Injection Through Unescaped CLI and Configuration Values

Content
View full analysis
0${SIM_PIN}") ``` SMS recipient and content from command-line arguments: ```bash cmd_sms_send() { local number="$1" message="${*:2}" local date length date=$(date "+%Y-%m-%d %H:%M:%S") length=${#message} ensure_interface || return 1 ensure_sim || return 1 get_tokens local resp resp=$(api_post "/sms/send-sms" "-1${number}${message}${length}1${date}0") ``` SMS index from a command-line argument: ```bash cmd_sms_delete() { local index="$1" ensure_interface || return 1 get_tokens local resp resp=$(api_post "/sms/delete-sms" "${index}") ``` PIN arguments used by PIN operations: ```bash cmd_pin_enter() { local pin="$1" ensure_interface || return 1 get_tokens local resp resp=$(api_post "/pin/operate" "0${pin}") ``` ```bash cmd_pin_disable() { local pin="$1" ensure_interface || return 1 get_tokens local resp resp=$(api_post "/pin/operate" "2${pin}") ``` ### T ...[truncated 2328 chars]
Remediation
View remediation
` with `>` - Quotes where values are used in attributes 3. Apply strict semantic validation before XML construction: ```bash [[ "$index" =~ ^[0-9]+$ ]] || return 1 [[ "$pin" =~ ^[0-9]{4,8}$ ]] || return 1 [[ "$number" =~ ^\+?[0-9]{3,20}$ ]] || return 1 ``` 4. Permit arbitrary valid SMS text only after XML encoding. Do not solve the issue by deleting characters from message content. 5. Validate generated XML locally before transmission and fail closed if serialization or parsing fails. 6. Add tests for ampersands, angle brackets, Unicode, multiline SMS messages, invalid indices, and invalid PIN formats. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/hilink.sh:7
Finding

Automatic Shell Execution from the Configuration File and Insecure SIM PIN Handling

Content
View full analysis
" && exit 1; cmd_pin_enter "$3" ;; disable) [ $# -lt 3 ] && echo "Usage: $0 pin disable " && exit 1; cmd_pin_disable "$3" ;; ``` The documentation recommends a shell-style configuration file: ```bash HILINK_GATEWAY=192.168.200.1 ``` It also documents PIN entry directly on the command line: ```bash scripts/hilink.sh pin enter 1234 scripts/hilink.sh pin disable 1234 scripts/hilink.sh pin status ``` ### Technical Analysis The script uses `source "$CONFIG_FILE"`, causing Bash to parse and execute the entire configuration file. The file is therefore not merely configuration data: command substitutions, function calls, redirections, and arbitrary shell commands placed in it execute whenever any Skill command starts. This becomes exploitable if another user, process, extracted archive, or compromised tool can create, replace, or modify `~/.config/hilink/config`. No ownership or permission checks are performed before sourcing it. SIM PINs can additionally be stored in plaintext through `HILINK_PIN` or supplied in command-line arguments. Command-line secrets may be exposed through: - Shell history. - Process listings while the command is running. - Agent or terminal logs. - Monitori ...[truncated 1869 chars]
Remediation
View remediation
&2 exit 1 ;; esac done < "$CONFIG_FILE" ``` 2. Validate all parsed values. Restrict the gateway to a valid IP address or explicitly supported hostname and validate subnet/IP fields using an appropriate parser. 3. Verify configuration security before reading it: - Require ownership by the current user. - Reject symbolic links where appropriate. - Reject group-writable or world-writable files. - Use `0700` permissions for `~/.config/hilink`. - Use `0600` permissions for the configuration file. 4. Do not store `HILINK_PIN` in the general configuration file by default. 5. Read sensitive PINs from a protected terminal prompt: ```bash read -r -s -p "SIM PIN: " pin printf '\n' >&2 ``` Alternatively, accept the PIN through a dedicated file descriptor or secret-management facility. 6. Validate PINs as digits with an appropriate supported length and avoid printing them. 7. Update `SKILL.md` so examples do not include real PINs on command lines and clearly document file-permission and secret-handling requirements. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (16)

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · SKILL.md (reported line 48)May include surrounding context.

Create udev rule

echo 'SUBSYSTEM=="net", ACTION=="add", ATTR{address}=="xx:xx:xx:xx:xx:xx", NAME="lte0"'
| sudo tee /etc/udev/rules.d/70-lte-modem.rules

text

## CLI Usage

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/api.md (reported line 57)May include surrounding context.

md
<request>
  <PageIndex>1</PageIndex>
  <ReadCount>20</ReadCount>
  <BoxType>1</BoxType>        <!-- 1=inbox, 2=outbox -->
  <SortType>0</SortType>
  <Ascending>0</Ascending>
  <UnreadPreferred>1</UnreadPreferred>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/api.md (reported line 102)May include surrounding context.

| GET | /api/ussd/get | Get USSD response |

xml
<!-- Send USSD -->
<request>
  <content>*#100#</content>
  <codeType>CodeType</codeType>

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill advertises operational shell-based capabilities but does not declare any tool scope or allowed-tools restrictions. In an agent environment, this creates unnecessary ambiguity about what execution surface the skill expects, increasing the chance of over-privileged or unintended command execution when handling modem operations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This skill handles highly privacy-sensitive data including SMS contents, phone numbers, SIM PINs, session cookies, CSRF tokens, and USSD/balance information, but it does not prominently warn users about exposure risks. In practice, these values may be echoed in terminals, shell history, logs, or agent transcripts, leading to credential and message disclosure.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 48)May include surrounding context.

Create udev rule

echo 'SUBSYSTEM=="net", ACTION=="add", ATTR{address}=="xx:xx:xx:xx:xx:xx", NAME="lte0"'
| sudo tee /etc/udev/rules.d/70-lte-modem.rules

text

## CLI Usage

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 82)May include surrounding context.

bash
# Get tokens
curl -s http://GATEWAY/api/webserver/SesTokInfo
# Returns: <SesInfo>cookie</SesInfo><TokInfo>csrf_token</TokInfo>

# Use in requests

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation includes destructive or high-impact actions such as deleting SMS and operating on the SIM PIN, but provides no warnings or safety guidance. In an autonomous or semi-autonomous agent workflow, this increases the chance of irreversible message loss, SIM lockout, or connectivity disruption from routine-looking API use.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The reference exposes a DHCP configuration write capability that expands the skill from modem messaging/status into broader network reconfiguration. In an agent setting, documenting this endpoint without clear scope restrictions can enable unintended gateway/IP changes that disrupt local connectivity or alter network behavior beyond the user’s likely intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

This code reads configuration from a user-controlled file and documents that the SIM PIN can be stored there, which involves access to sensitive credential material. While the script uses the PIN for its intended modem-management purpose, there is no nearby disclosure or warning about storing or using the PIN from disk.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 100)May include surrounding context.

md
if [ "$state" != "up" ] || [ "$has_ip" -eq 0 ]; then
        echo "Bringing up ${iface}..." >&2
        sudo ip addr add "$STATIC_IP" dev "$iface" 2>/dev/null || true
        sudo ip link set "$iface" up 2>/dev/null
        sleep 2
    fi

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/hilink.sh (reported line 53)May include surrounding context.

sh
if [ "$state" != "up" ] || [ "$has_ip" -eq 0 ]; then
        echo "Bringing up ${iface}..." >&2
        sudo ip addr add "$STATIC_IP" dev "$iface" 2>/dev/null || true
        sudo ip link set "$iface" up 2>/dev/null
        sleep 2
    fi

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/hilink.sh (reported line 54)May include surrounding context.

sh
if [ "$state" != "up" ] || [ "$has_ip" -eq 0 ]; then
        echo "Bringing up ${iface}..." >&2
        sudo ip addr add "$STATIC_IP" dev "$iface" 2>/dev/null || true
        sudo ip link set "$iface" up 2>/dev/null
        sleep 2
    fi

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/hilink.sh (reported line 119)May include surrounding context.

sh
if [ "$state" != "up" ] || [ "$has_ip" -eq 0 ]; then
        echo "Bringing up ${iface}..." >&2
        sudo ip addr add "$STATIC_IP" dev "$iface" 2>/dev/null || true
        sudo ip link set "$iface" up 2>/dev/null
        sleep 2
    fi

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

The script sends sensitive commands and data, including SIM PINs, SMS content, USSD requests, session cookies, and verification tokens, over unencrypted HTTP to the modem API. In the skill context this is expected for HiLink devices, but it still creates exposure to interception or manipulation by a local attacker on the same host or network segment, especially because the gateway address is configurable via a sourced config file.

Content

Scanner excerpt · scripts/hilink.sh (reported line 139)May include surrounding context.

sh
api_post() {
    local endpoint="$1" data="$2"
    curl -s --connect-timeout 10 -X POST "${API}${endpoint}" \
        -H "Cookie: ${SESSION}" \
        -H "__RequestVerificationToken: ${TOKEN}" \
        -H "Content-Type: application/xml" \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The delete command performs an irreversible mailbox modification via the modem API and only reports success after the fact. There is no confirmation prompt, pre-action warning, or cautionary documentation in the usage text to alert the user before deleting SMS content.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.