Back to skill

Security audit

Ssh Deploy Skill

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a legitimate SSH deployment skill, but it needs Review because its defaults and templates can expose production SSH sessions and execute mutable remote installer code with high privileges.

Install only if you are comfortable granting the skill authority to run commands, upload files, and change package repositories and services on your servers. Use --strict for SSH host-key verification, avoid password entries in inventory.json, review templates before running them, and replace curl-to-bash or unpinned dependency installs with pinned, verified sources for production use.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T03 · Remote Payload Retrieval and Execution

Error
Location
templates/install_nodejs.sh:9
Finding

Unverified Remote Scripts Are Executed Directly by a Shell

Content
View full analysis
Remediation
View remediation
&2; exit 1 ;; esac tmp_script="$(mktemp)" trap 'rm -f "$tmp_script"' EXIT curl --fail --silent --show-error --location \ "https://deb.nodesource.com/setup_${NODE_VERSION}.x" \ --output "$tmp_script" echo " $tmp_script" | sha256sum --check - bash "$tmp_script" ``` The digest must be obtained through a trusted release process and updated only after reviewing the new script. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
scripts/deploy.py:106
Finding

SSH Host-Key Verification Is Disabled by Default

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/inventory.py:147
Finding

Plaintext SSH Passwords Can Be Persisted Without Enforced File Permissions

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/setup.sh:37
Finding

Paramiko Is Installed Without Version or Integrity Pinning

Content
View full analysis
&1 | grep -q "Successfully"; then echo "paramiko installed in user directory" else echo "paramiko installation failed" exit 1 fi ``` The Skill metadata and setup documentation also identify `paramiko` without a reviewed version or artifact hash. ### Technical Analysis The setup process asks pip to resolve the latest available `paramiko` package and its transitive dependencies from the caller's configured package indexes. No exact version, lock file, cryptographic artifact hash, or approved index is enforced. This creates a mutable supply-chain boundary: the code imported by the Skill can differ between installations even when the Skill itself has not changed. A compromised package index, maliciously configured mirror, upstream package compromise, or unsafe future dependency release can introduce arbitrary code into the deployment environment. Python package installation may execute build backend or installation logic. Later, `deploy.py` imports Paramiko in a process that reads SSH configuration and private keys and establishes privileged administrative sessions, increasing the consequence of dependency compromise. ### Attack Path 1. The setup script does not find a usable system Paramiko package and falls back to pip. 2. Pip resolves `paramiko` and transitive dependencies using a configured, mutable package index. 3. An attacker comprom ...[truncated 1088 chars]
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (177)

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 60)May include surrounding context.

text

When `--strict` is used:
- Loads `~/.ssh/known_hosts`
- Rejects unknown or changed host keys
- First connection to a new server will fail; you must manually verify fingerprint first
- Prevents man-in-the-middle attacks

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 272)May include surrounding context.

text

When `--strict` is used:
- Loads `~/.ssh/known_hosts`
- Rejects unknown or changed host keys
- First connection to a new server will fail; you must manually verify fingerprint first
- Prevents man-in-the-middle attacks

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 329)May include surrounding context.

text

When `--strict` is used:
- Loads `~/.ssh/known_hosts`
- Rejects unknown or changed host keys
- First connection to a new server will fail; you must manually verify fingerprint first
- Prevents man-in-the-middle attacks

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.zh-CN.md (reported line 159)May include surrounding context.

text

When `--strict` is used:
- Loads `~/.ssh/known_hosts`
- Rejects unknown or changed host keys
- First connection to a new server will fail; you must manually verify fingerprint first
- Prevents man-in-the-middle attacks

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/troubleshooting.md (reported line 216)May include surrounding context.

text

When `--strict` is used:
- Loads `~/.ssh/known_hosts`
- Rejects unknown or changed host keys
- First connection to a new server will fail; you must manually verify fingerprint first
- Prevents man-in-the-middle attacks

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/troubleshooting.md (reported line 219)May include surrounding context.

text

When `--strict` is used:
- Loads `~/.ssh/known_hosts`
- Rejects unknown or changed host keys
- First connection to a new server will fail; you must manually verify fingerprint first
- Prevents man-in-the-middle attacks

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

The manual inventory example stores the SSH private key path in ~/.ssh-deploy/inventory.json, and the README also notes elsewhere that passwords may be stored in plaintext in the same inventory. While a key path alone is not a secret, encouraging sensitive connection material to be centrally recorded in a user-managed JSON file can increase the blast radius of local compromise and normalize insecure credential handling practices.

Content

Scanner excerpt · README.md (reported line 231)May include surrounding context.

md
"host": "1.2.3.101",
      "port": 22,
      "user": "deploy",
      "ssh_key": "~/.ssh/id_rsa_prod",
      "groups": ["web", "production"],
      "tags": ["aliyun", "east-china"]
    }

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description promises a full-featured SSH-based deployment and installation tool. However, the supplied code chunk does not implement any of those capabilities; it is only package metadata with a name and version. This is a material mismatch between the declared purpose and the actual behavior visible in the code provided.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents a full remote deployment system with multi-server orchestration and software installation capabilities. The supplied code chunk instead only manages a local inventory of SSH server definitions. Its primary functions are loading/saving server records, importing entries from the user's SSH config, and filtering/listing servers by group/tag/name. While inventory management is related to SSH server management, it is only a supporting subset and does not substantiate the much broader deployment/install claims. Additionally, the code reads ~/.ssh/config and writes to ~/.ssh-deploy/inventory.json, which are local resource accesses not reflected in the declared permissions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The declared description presents the skill as an SSH-based remote deployment tool with multi-server and batch deployment capabilities. However, the supplied code chunk is a template/configuration manager: it stores shell-script templates and mirror config text, and exposes helper functions plus a CLI to list or output them. While the embedded templates relate to installing Git, Docker, MySQL, PostgreSQL, Nginx, Node.js, Redis, and Python, this chunk itself does not connect to remote servers, orchestrate deployments, manage multiple hosts, or execute installations. The domestic mirror optimization portion is represented accurately, but the primary purpose and major capabilities described are not implemented in this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The declared description presents a broad remote deployment and package installation tool, but this specific code only performs base system preparation on the local machine. It modifies OS package repository files, refreshes package indexes, installs a few basic utilities, and emits informational text about optional mirror settings. While the domestic mirror optimization aspect partially matches, the main advertised capabilities—SSH-based remote deployment, multi-server management, batch deployment, and installation of many application stacks—are not implemented in this chunk. Therefore the description materially overstates what this code actually does.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · references/best-practices.md (reported line 265)May include surrounding context.

bash
cat install.sh | python3 scripts/deploy.py exec web-01 "bash -s" && \
python3 scripts/deploy.py exec web-01 "systemctl is-active nginx && curl -f http://localhost"

Automated rollback

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · references/best-practices.md (reported line 367)May include surrounding context.

md
6. **Firewall**: `iptables -L` or `firewall-cmd --list-all`
7. **SELinux** (RHEL): `restorecon -R -v ~/.ssh`
8. **Disk space**: `df -h`
9. **Mirror connectivity**: `curl -I https://mirrors.aliyun.com`
10. **Logs**: `/var/log/auth.log` or `/var/log/secure`

See `docs/troubleshooting.md` for detailed solutions.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/mirrors.md (reported line 122)May include surrounding context.

npm config set registry https://registry.npmjs.org/

text

**Global config**: `/etc/npmrc` or `~/.npmrc`

### Yarn

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · references/mirrors.md (reported line 137)May include surrounding context.

tps://registry.npmmirror.com

Verify

npm config get registry

Reset to official

npm config set registry https://registry.npmjs.org/

text

**Global config**: `/etc/npmrc` or `~/.npmrc`

### Yarn

```bash
yarn config set registry https://registry.npmmirror.com
yarn config get registry

Config file: ~/.yarnrc or ~/.yarnrc.yml

Go Modules

bash
# Add to ~/.bashrc or ~/.profile
echo 'export GOPROXY=https://goproxy.cn,direct' >> ~/.bashrc
source ~/.bashrc

# Verify
go env GOPROXY
# Should output: https://goproxy.cn,direct

Rust (rustup)

bash
# In ~/.cargo/config.toml
[source.crates-io]
replace-with = 'tuna'

[source.tuna]
registry = "https://mirrors.tuna.tsinghua.edu.cn/git/crates.io-index.git"

Java Maven

Edit ~/.m2/settings.xml:

xml
<settings>
  <mirrors>
    <mirror>
      <id>aliyunmaven</id>
      <mirrorOf>*</mirrorOf>
      <name>Aliyun Maven Mirror</name>
      <url>https://maven.aliyun.com/repository/public</url>
    </mirror>
  </mi

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/mirrors.md (reported line 260)May include surrounding context.

bash
# Debian/Ubuntu
apt-get clean
rm -rf /var/lib/apt/lists/*
apt-get update

# CentOS/RHEL

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/mirrors.md (reported line 265)May include surrounding context.

bash
# Debian/Ubuntu
apt-get clean
rm -rf /var/lib/apt/lists/*
apt-get update

# CentOS/RHEL

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/mirrors.md (reported line 260)May include surrounding context.

bash
# Debian/Ubuntu
apt-get clean
rm -rf /var/lib/apt/lists/*
apt-get update

# CentOS/RHEL

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/mirrors.md (reported line 265)May include surrounding context.

CentOS/RHEL

yum clean all rm -rf /var/cache/yum yum makecache

text

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 28)May include surrounding context.

md
│
    ├─ Authentication Failed?
    │   ├─ Manual ssh test → Works?
    │   │   └─ Check ~/.ssh/id_rsa permissions (600)
    │   │   └─ Check server ~/.ssh/authorized_keys (600)
    │   │   └─ Check /etc/ssh/sshd_config
    │   │

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 206)May include surrounding context.

md
│
    ├─ Authentication Failed?
    │   ├─ Manual ssh test → Works?
    │   │   └─ Check ~/.ssh/id_rsa permissions (600)
    │   │   └─ Check server ~/.ssh/authorized_keys (600)
    │   │   └─ Check /etc/ssh/sshd_config
    │   │

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 340)May include surrounding context.

md
│
    ├─ Authentication Failed?
    │   ├─ Manual ssh test → Works?
    │   │   └─ Check ~/.ssh/id_rsa permissions (600)
    │   │   └─ Check server ~/.ssh/authorized_keys (600)
    │   │   └─ Check /etc/ssh/sshd_config
    │   │

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.zh-CN.md (reported line 33)May include surrounding context.

md
│
    ├─ Authentication Failed?
    │   ├─ Manual ssh test → Works?
    │   │   └─ Check ~/.ssh/id_rsa permissions (600)
    │   │   └─ Check server ~/.ssh/authorized_keys (600)
    │   │   └─ Check /etc/ssh/sshd_config
    │   │

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.zh-CN.md (reported line 46)May include surrounding context.

md
│
    ├─ Authentication Failed?
    │   ├─ Manual ssh test → Works?
    │   │   └─ Check ~/.ssh/id_rsa permissions (600)
    │   │   └─ Check server ~/.ssh/authorized_keys (600)
    │   │   └─ Check /etc/ssh/sshd_config
    │   │

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.zh-CN.md (reported line 61)May include surrounding context.

md
│
    ├─ Authentication Failed?
    │   ├─ Manual ssh test → Works?
    │   │   └─ Check ~/.ssh/id_rsa permissions (600)
    │   │   └─ Check server ~/.ssh/authorized_keys (600)
    │   │   └─ Check /etc/ssh/sshd_config
    │   │

Static analysis

No suspicious patterns detected.