Back to skill

Security audit

VibeTunnel

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward VibeTunnel REST API reference for managing terminal sessions, with expected local API calls and some install/usage risks users should understand.

Install this only if you intend to let the agent control VibeTunnel sessions. Keep `VT_URL` pointed at a trusted server, review commands before sending them to a session, and be careful with delete or cleanup examples because they remove session state. Consider pinning or independently verifying the npm package in stricter environments.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:5
Finding

Unpinned Third-Party npm Package Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 5
Vulnerability Type: Unpinned and mutable third-party dependency
Risk Level: Medium

Complete Code Snippet:

yaml
metadata: {"clawdbot":{"emoji":"🖥️","requires":{"bins":["vibetunnel","curl","jq"]},"primaryEnv":"VT_URL","install":[{"id":"vibetunnel","kind":"node","package":"vibetunnel","bins":["vibetunnel"],"label":"Install VibeTunnel (npm)"}]}}

Technical Analysis

The installation metadata specifies the npm package vibetunnel without an exact version or integrity hash. Consequently, the artifact installed in the future can differ from the artifact available when this Skill was reviewed. The GitHub homepage reference does not cryptographically bind the npm package to a reviewed source revision.

This creates a supply-chain risk: compromise of the package publisher, npm account, package release process, registry resolution, or a transitive dependency could introduce malicious code. Depending on the installer, malicious npm lifecycle scripts or package code could execute during installation or later when the vibetunnel binary is invoked.

Attack Path

  1. An attacker compromises the npm publisher account, release pipeline, package source, or a transitive dependency used by vibetunnel.
  2. The attacker publishes a malicious package version under the expected package name.
  3. A user installs the Skill after that release is published.
  4. Because no exact version or integrity value is specified, the installer resolves the attacker-controlled release.
  5. Malicious code executes through an npm lifecycle hook or when the installed vibetunnel executable is invoked.
  6. The code operates with the privileges of the user or automation account performing the installation or execution.

Impact Assessment

Successful exploitation could provide arbitrary code execution with the installing user's privileges. The resulting access could include re ...[truncated 303 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin vibetunnel to a reviewed exact version rather than relying on mutable registry resolution.
  • Use a lockfile or equivalent integrity mechanism containing registry-resolved cryptographic hashes.
  • Verify npm package provenance, publisher identity, release signatures, and the correspondence between the package artifact and the referenced source repository.
  • Review direct and transitive dependencies before updating the pinned version.
  • Disable npm lifecycle scripts during installation where operationally possible, and explicitly review any scripts that must be enabled.
  • Perform installation and execution in a least-privileged, isolated environment without unnecessary credentials or host filesystem access.
  • Introduce an update process that scans and tests each proposed dependency version before changing the pin.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (7)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 33)May include surrounding context.

Create Session

bash
curl -s -X POST ${VT_URL:-http://localhost:8080}/api/sessions \
  -H "Content-Type: application/json" \
  -d '{"command": ["zsh", "-l", "-i"], "name": "my-session", "workingDir": "/path/to/dir"}' | jq .

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

Create Session

bash
curl -s -X POST ${VT_URL:-http://localhost:8080}/api/sessions \
  -H "Content-Type: application/json" \
  -d '{"command": ["zsh", "-l", "-i"], "name": "my-session", "workingDir": "/path/to/dir"}' | jq .

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 82)May include surrounding context.

Create Session

bash
curl -s -X POST ${VT_URL:-http://localhost:8080}/api/sessions \
  -H "Content-Type: application/json" \
  -d '{"command": ["zsh", "-l", "-i"], "name": "my-session", "workingDir": "/path/to/dir"}' | jq .

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file documents a DELETE operation that removes terminal sessions, but it provides no warning that the action is destructive or irreversible for the targeted session. Under the markdown-file criteria for missing user warnings, behaviors that can affect user data or system state should be disclosed to the user.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 57)May include surrounding context.

Send Input

bash
curl -s -X POST ${VT_URL:-http://localhost:8080}/api/sessions/<id>/input \
  -H "Content-Type: application/json" \
  -d '{"text": "ls -la\n"}' | jq .

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 66)May include surrounding context.

Resize Session

bash
curl -s -X POST ${VT_URL:-http://localhost:8080}/api/sessions/<id>/resize \
  -H "Content-Type: application/json" \
  -d '{"cols": 150, "rows": 40}' | jq .

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The cleanup example enumerates exited sessions and deletes them in bulk, but the surrounding documentation does not warn that this permanently removes multiple sessions at once. This is a clear markdown-level omission of a warning for behavior that affects user data/system state.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.