Back to skill

Security audit

Vpn Proxy Manager

Security checks for vulnerabilities and agentic risk

Overview

This proxy skill has a coherent purpose, but it makes under-disclosed persistent shell changes and includes unsafe command/process handling that users should review before installing.

Review this skill before installing. It should remove or make opt-in the ~/.bashrc write, replace eval-based wrap execution with direct argument execution, narrow process management to a recorded V2Ray PID, and clearly document that proxy changes and background processes may affect local networking.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/v2ray-proxy.sh:180
Finding

Arbitrary Command Execution Through Unsafe eval Usage

Content
View full analysis

Vulnerability Details

File Location: scripts/v2ray-proxy.sh, lines 180–194
Vulnerability Type: OS command injection
Risk Level: High

Vulnerable Code

bash
wrap() {
    local cmd="$*"
    
    log_info "执行命令: $cmd"
    
    # 检查是否需要代理
    if check_network; then
        log_info "网络正常,直接执行..."
        eval "$cmd"
        return $?
    fi
    
    # 需要代理,开启后执行
    log_info "开启代理后执行..."
    proxy_on
    
    local result=0
    eval "$cmd" || result=$?
    
    log_info "命令执行完成,关闭代理..."
    proxy_off
    
    return $result
}

Technical Analysis

The wrap function combines all supplied arguments into a single string using "$*", then passes that string to eval. Unlike direct argument-array execution, eval asks the shell to parse the resulting string again. Shell metacharacters, command substitutions, redirections, pipelines, and additional commands embedded in an argument therefore become executable syntax.

Quoting "$cmd" at the point where it is passed to eval does not prevent injection because eval deliberately performs another shell parsing pass.

Attack Path

  1. An attacker controls or influences arguments passed to the wrap command, directly or through another workflow.
  2. The attacker includes shell syntax such as command substitution or a command separator in an argument.
  3. The script flattens the argument list into cmd with local cmd="$*".
  4. Either network branch reaches eval "$cmd".
  5. The shell reparses the injected syntax and executes the unintended command.

For example, a literal argument containing $(unintended-command) would be evaluated as command substitution rather than being passed unchanged to the intended program.

Impact Assessment

Successful exploitation provides arbitrary command execution with the privileges of the user running the script. The attacker could read or modify files available to t ...[truncated 277 chars]

Remediation
View remediation

Remediation Suggestions

Preserve the original argument boundaries and execute the command directly without eval:

bash
wrap() {
    local result=0

    log_info "Executing wrapped command"

    if check_network; then
        log_info "Network is available; executing directly"
        "$@"
        return $?
    fi

    log_info "Enabling proxy before execution"
    proxy_on

    "$@" || result=$?

    log_info "Command completed; disabling proxy"
    proxy_off

    return "$result"
}

Additional hardening measures:

  • Reject an empty command before attempting execution.
  • Do not reconstruct commands as strings.
  • If only specific programs are expected, enforce an allowlist of permitted executable names.
  • Avoid logging untrusted arguments without safe escaping, especially when logs may be consumed by terminals or parsers.
  • Run wrapped commands with the minimum required operating-system privileges.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/v2ray-proxy.sh:25
Finding

Overbroad Process Matching Can Terminate Unrelated Processes

Content
View full analysis

Vulnerability Details

File Location: scripts/v2ray-proxy.sh, lines 25–27 and 59–60
Vulnerability Type: Unsafe process identification and termination
Risk Level: Medium

Vulnerable Code

bash
# 检查v2ray是否运行
is_running() {
    pgrep -f "xray.*config" > /dev/null 2>&1
}
bash
pkill -f "xray.*config" || true
pkill -f "v2rayN" || true

Technical Analysis

The script identifies and terminates processes by applying broad regular expressions to entire command lines through pgrep -f and pkill -f. These expressions are not restricted to the configured V2Ray directory, the expected executable path, a process started by this script, or a securely recorded process identifier.

Consequently, any process visible and signalable by the invoking user whose command line contains a matching sequence may be treated as the managed V2Ray instance. The v2rayN match is especially broad because it can match any command line containing that substring.

The same weak matching affects status detection: an unrelated matching process can cause is_running to return success, preventing startup or producing an incorrect status.

Attack Path

  1. A legitimate unrelated process, or a process intentionally created by another local actor, runs with xray followed later by config in its command line, or contains v2rayN.
  2. The user invokes stop, off, or an automatic workflow that calls stop_v2ray.
  3. pkill -f scans full command lines and selects every matching process the invoking user is permitted to signal.
  4. The script terminates those processes without confirming that they belong to the configured V2Ray installation.

Impact Assessment

Exploitation can cause local denial of service by terminating unrelated Xray, V2Ray, or coincidentally matching processes owned by the invoking user. This may interrupt other network sessions, proxy services, development tasks, or applications.

T ...[truncated 297 chars]

Remediation
View remediation

Remediation Suggestions

Manage the exact process started by the script rather than searching all command lines:

  1. Capture the PID immediately after launching V2Ray.
  2. Store it in a user-owned PID file located in a directory with restrictive permissions, such as a private runtime directory.
  3. Before signaling the PID, verify that:
    • The PID is numeric and currently exists.
    • The process is owned by the expected user.
    • Its executable resolves to the expected binary under V2RAY_DIR.
    • Its start time or another process identity attribute matches the recorded instance, reducing PID-reuse risk.
  4. Send a graceful termination signal to that validated PID and wait for shutdown before considering a forced termination.
  5. Remove the PID file after confirmed shutdown.

Where available, a user-level service manager such as systemd should be preferred because it provides scoped process lifecycle management without broad command-line matching.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (9)

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
89% confidence
Finding

This YARA hit is not evidence of malware payloads, but it does correctly identify shell startup file modification as a persistence mechanism. In this skill context, the content written is limited, yet the act of silently appending to ~/.bashrc remains a real security concern because startup-file persistence is a common abuse primitive and exceeds user-visible session-only proxy configuration.

Content

Scanner excerpt · scripts/v2ray-proxy.sh (reported line 92)May include surrounding context.

sh
proxy="$PROXY_URL"
    export HTTP_PROXY="$PROXY_URL"
    export HTTPS_PROXY="$PROXY_URL"
    
    # 设置no_proxy(跳过本地地址)
    export no_proxy="localhost,127.0.0.1,::1,*.local"
    export NO_PROXY="$no_proxy"
    
    log_info "系统代理已开启: http_proxy=$PROXY_URL"
    
    # 持久化到bashrc(可选)
    if ! grep -q "V2RAY_PROXY" ~/.bashrc 2>/dev/null; then
        echo "" >> ~/.bashrc
        echo "# V2Ray Proxy (managed by OpenClaw)" >> ~/.bashrc
        echo "export V2RAY_PROXY=1" >> ~/.bashrc
    fi
}

# 清除系统代理
disable_system_proxy() {
    log_info "清除系统代理..."
    
    unset http_proxy https_proxy HTTP_PROXY HTTPS_PROXY
    unset no_proxy NO_PROXY
    
    log_info "系统代理已清除"
}

# 测试代理连接
test_proxy() {
    log_info "测试代理连接..."
    
    # 测试直连
    local direct_result=$(curl -s --connect-timeout 5 -o /dev/null -w "%{http_code}" https://www.google.com 2>/dev/null || echo "000")

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README promotes automatic enabling/disabling of system proxy settings based on network reachability, but it does not warn users that this can alter global network behavior for other applications, disrupt connectivity, or unintentionally route traffic through the proxy. In a proxy-management skill, these side effects are expected functionality, but omitting clear warnings and scope limitations increases the chance of unsafe or surprising system-wide changes.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill documents shell-based execution (./scripts/v2ray-proxy.sh ...) but does not declare any permissions or allowed-tools scope in the skill manifest. This creates an authorization gap where an agent or reviewer cannot clearly determine the intended execution boundaries, increasing the risk of unintended shell access or over-privileged execution when the skill is invoked.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/v2ray-proxy.sh (reported line 38)May include surrounding context.

sh
log_info "启动 V2Ray..."
    cd "$V2RAY_DIR"
    nohup ./v2rayN > /dev/null 2>&1 &
    sleep 2
    
    if is_running; then

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script silently modifies ~/.bashrc even though its declared behavior is system proxy management, not persistent shell-profile changes. Hidden persistence in shell startup files can create long-lived behavioral changes, reduce user visibility, and establish a foothold for future environment-based manipulation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Persisting configuration changes to the user's shell startup file without warning or consent is unsafe because it creates durable side effects outside the current session. Even though the current payload is limited, this pattern is dangerous in agent skills because shell init files are high-value persistence points frequently abused for stealthy post-execution changes.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The wrap() function executes arbitrary user-supplied text via eval, which enables shell metacharacter expansion, command chaining, and injection if arguments are influenced by untrusted input. In a proxy-management skill, a generic command runner materially expands the attack surface beyond the stated purpose and can be abused to execute unintended commands under the user's account.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

wrap() provides arbitrary command execution with only a log message and no safety interstitial, validation, or restriction. Because it uses eval, the danger is greater than a normal command launcher: crafted input can alter execution flow and run multiple commands, making the skill substantially more dangerous than ordinary proxy tooling.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest uses Chinese-only natural-language fields for the skill name and description. This can violate a language/locale policy when the skill does not indicate that the user can choose their preferred language or that the locale restriction is intentional.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.