Back to skill

Security audit

sjht-ssh-ops

Security checks for vulnerabilities and agentic risk

Overview

This SSH operations skill is coherent, but it needs review because it automates high-impact server access while handling passwords and SSH trust checks unsafely.

Install only if you are comfortable with an agent managing SSH keys and remote server access. Before use, review each generated command, avoid root unless necessary, do not paste reusable passwords into chat or logs, verify host keys out of band, and consider changing the script to require manual dependency installation and stricter host/user/key-name validation.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/ssh-key-setup.sh:52
Finding

SSH Destination Option Injection Through Unvalidated User and Host Arguments

Content
View full analysis
[user]" return 1 fi if [ ! -f "$SSH_DIR/$DEFAULT_KEY" ]; then echo "❌ 私钥不存在,请先运行 gen" return 1 fi if ! command -v sshpass &>/dev/null; then echo "正在安装 sshpass..." if command -v apt-get &>/dev/null; then DEBIAN_FRONTEND=noninteractive apt-get install -y -qq sshpass 2>&1 elif command -v yum &>/dev/null; then yum install -y -q sshpass 2>&1 fi fi echo "📤 部署公钥到 ${user}@${host} ..." sshpass -p "$SSHPASS" ssh-copy-id -o StrictHostKeyChecking=no "${user}@${host}" 2>&1 echo "✅ 公钥已部署" } cmd_test() { local host="$1" local user="${2:-root}" if [ -z "$host" ]; then echo "❌ 用法: test [user]" return 1 fi echo "🔗 测试免密登录 ${user}@${host} ..." if ssh -o ConnectTimeout=5 -o BatchMode=yes "${user}@${host}" "echo '✅ 免密登录成功' && hostname" 2>&1; then echo "✅ 连接正常" else echo "❌ 免密登录失败,请检查公钥是否已部署" return 1 fi } cmd_info() { local host="$1" local user="${2:-root}" if [ -z "$host" ]; then echo "❌ 用法: info [user]" return 1 fi echo "📊 远程主机信息: ${user}@${host}" ssh -o ConnectTimeout=5 "${user}@${host}" bash -c ' echo " 主机名: $(hostname)" echo " 系统: $(cat /etc/os-release 2>/dev/null | grep PRETTY_NAME | cut -d= -f2 | tr -d \"\")" echo " 内核: $(uname -r)" echo " 架构: $(uname -m)" echo " 内存: $(free -h | awk "/^Mem:/{print \$2\" total, \"\$7\" available\"}")" echo " 磁盘: $(df -h / | awk "NR==2{print \$2\" total ...[truncated 1904 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/ssh-key-setup.sh:24
Finding

Path Traversal in SSH Key Name Allows File Access Outside ~/.ssh

Content
View full analysis
&1 echo "✅ 密钥已生成: $keyfile" echo " 公钥:" cat "${keyfile}.pub" } cmd_pub() { local name="${1:-$DEFAULT_KEY}" local keyfile="$SSH_DIR/${name}.pub" if [ -f "$keyfile" ]; then cat "$keyfile" else echo "❌ 公钥不存在: $keyfile" return 1 fi } ``` ### Technical Analysis The optional key name is concatenated directly with `$HOME/.ssh` without restricting path separators, absolute-path components, or `..` traversal sequences. Shell quoting does not enforce that the resolved file remains inside the intended SSH directory. In `cmd_gen`, a traversal value can direct `ssh-keygen` to create private and public key files outside `~/.ssh`, subject to filesystem permissions and `ssh-keygen` overwrite behavior. In `cmd_pub`, the same weakness can print any readable file whose selected path ends in `.pub`. This access exceeds the minimum filesystem scope required for the declared key-management functionality, which only requires managing key files under the user's SSH directory. ### Attack Path 1. An attacker influences the optional `name` supplied to `gen` or `pub`. 2. The attacker provides a traversal value such as `../../tmp/chosen-key`. 3. The script constructs a path such as `$HOME/.ssh/../../tmp/chosen-key`. 4. The operating system resolves the traversal outside `$HOME/.ssh`. 5. For `gen`, `ssh-keygen` creates key material at the attacker-selected writabl ...[truncated 541 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/ssh-key-setup.sh:76
Finding

Disabled SSH Host-Key Verification During Credential-Based Deployment

Content
View full analysis
&1 echo "✅ 公钥已部署" ``` ### Technical Analysis `StrictHostKeyChecking=no` disables the normal check that confirms the remote endpoint presents the expected SSH host key. This occurs during a password-authenticated operation, when the script supplies `SSHPASS` to `ssh-copy-id`. Without host authentication, DNS poisoning, network interception, routing manipulation, or a malicious endpoint at the supplied address can cause the client to connect to an impostor. The connection may still be encrypted, but encryption alone does not establish that the remote party is the intended server. ### Attack Path 1. The user invokes `deploy` with a password in `SSHPASS`. 2. An attacker redirects or intercepts traffic to the requested host, or controls the resolved endpoint. 3. The attacker presents an untrusted SSH host key. 4. `StrictHostKeyChecking=no` causes the client to proceed without requiring verification. 5. The password-authentication exchange is conducted with the attacker-controlled SSH endpoint, allowing that endpoint to capture authentication material or otherwise impersonate the intended server. ### Impact Assessment An active network attacker or malicious destination can impersonate the remote server during key deployment. This can expose the remote account password and direct public-key installation attempts to an unauthorized host. Compromise of the password may grant the attacker the same remote privileges as the targeted account, which defaults to `root` in this script. ]]>
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/ssh-key-setup.sh:76
Finding

SSH Password Exposed Through Process Arguments and Incomplete Environment Cleanup

Content
View full analysis
&1 ``` Related documented invocation: ```bash SSHPASS='密码' bash /scripts/ssh-key-setup.sh deploy [user] ``` Related security guidance: ```markdown - `SSHPASS` 环境变量用完即 unset,不要持久化到文件 - 私钥(`id_ed25519`)权限必须是 600,`~/.ssh/` 权限必须是 700 - 不要在聊天记录中存储密码,使用时设环境变量 - 部署完成后验证免密登录,确认后再 unset 密码 ``` ### Technical Analysis The script expands the secret into the `sshpass -p` command-line argument. Depending on the platform and `sshpass` implementation, command-line secrets may be observable through process inspection, diagnostic tooling, audit systems, or execution logs. The documentation states that the environment variable should be unset, but the script does not perform an `unset`. More importantly, a child Bash process cannot remove an exported variable from its parent shell. The example scopes the assignment to one command when copied exactly, which limits persistence, but Agent tooling, logging, transcripts, wrappers, or alternative invocations may still retain the literal secret. The example itself also encourages placing a plaintext password directly in a command string. ### Attack Path 1. A user or Agent constructs the documented command with a plaintext password. 2. The shell, Agent transcript, orchestration layer, or command logger records the command string. 3. The script expands the password into `sshpass -p`. 4. A local observer, monitoring tool, or retained log captures the password from the command or process metadata. 5. The exposed credential is reused to authenticate to the remote account. ### Impact Assessment Credential disclosure could grant an attacker the privileges associated with the remote SSH account ...[truncated 314 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The documented behavior does not fully disclose that the workflow may install local packages such as sshpass, which changes the host environment and expands impact beyond simple SSH key deployment. This mismatch is dangerous because operators may invoke the skill expecting remote-only setup while it performs privileged local package-management actions and encourages broad remote command execution.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

bash /scripts/ssh-key-setup.sh gen

text

默认生成 `~/.ssh/id_ed25519`。如果已存在会提示。

### 2. 部署公钥到远程主机

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill exposes shell-capable behavior but does not declare any tool scope or allowed-tools boundary. In an agent setting, missing explicit permission constraints increases the chance of unintended shell execution or broader command use than reviewers and users expect.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Broad trigger phrases like '服务器管理' and '运维' can cause the skill to activate for loosely related requests, leading an agent to select a high-risk SSH/remote-operations skill unnecessarily. Because this skill handles credentials and remote administration, accidental invocation materially raises the chance of sensitive actions being proposed or executed in the wrong context.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/ssh-key-setup.sh (reported line 33)May include surrounding context.

sh
cat "${keyfile}.pub"
        return 0
    fi
    mkdir -p "$SSH_DIR" && chmod 700 "$SSH_DIR"
    ssh-keygen -t "$KEY_TYPE" -f "$keyfile" -N "" -C "openclaw@$(hostname)" 2>&1
    echo "✅ 密钥已生成: $keyfile"
    echo "   公钥:"

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The deploy function silently installs sshpass on the local machine if it is missing, which expands the skill's effects from SSH key management into local package management. That behavior can change the host system state unexpectedly, may require elevated privileges, and increases supply-chain and operational risk in environments where agent skills should not modify the local machine without explicit consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Using sshpass with the SSHPASS environment variable exposes a plaintext password to local processes, shell history/workflows, crash logs, and CI/runtime environments where environment variables may be inspected or inherited. In this skill context, the credential is used to access remote servers, so disclosure can directly enable unauthorized server login and lateral movement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file contains user-facing natural language exclusively in Chinese, including the changelog header and feature descriptions. Under the language/locale policy rule, forcing a specific language without user opt-in or documented justification is a policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file’s natural-language strings, comments, usage text, and help output are entirely in Chinese. The policy calls for flagging language or locale constraints when the skill forces a specific language without user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.