Back to skill

Security audit

deer-flow-manager

Security checks for vulnerabilities and agentic risk

Overview

This DeerFlow management skill is coherent, but it tells users to run high-impact installation and update commands with weak verification and limited safety guidance.

Review commands before running them. Prefer pinned DeerFlow releases or verified commits, inspect downloaded installer scripts before execution, avoid sudo -E for remote scripts, back up config.yaml/.env/logs before uninstall or update cleanup, and do not paste raw API keys into chat or store them in broadly readable files.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:130
Finding

Unverified Remote Installer Scripts Are Executed Directly

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
SKILL.md:165
Finding

Mutable Upstream Repository Code Is Executed Without Version or Integrity Pinning

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:38
Finding

API Key Collection and Plaintext Configuration Lack Secret-Handling Safeguards

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (20)

Chaining Abuse

High
Category
Tool Misuse
Confidence
96% confidence
Finding

This finding captures the dangerous composition of fetching remote content and immediately executing it with elevated privileges. The chaining is what makes the issue severe: users are not given a chance to inspect the script, and any compromise of the source leads directly to root-level code execution.

Content

Scanner excerpt · SKILL.md (reported line 143)May include surrounding context.

md
sudo apt install -y curl git make nginx python3.12 python3-pip

# 安装 Node.js 和 pnpm
curl -fsSL https://deb.nodesource.com/setup_22.x | sudo -E bash -
sudo apt install -y nodejs
npm install -g pnpm

Chaining Abuse

High
Category
Tool Misuse
Confidence
94% confidence
Finding

This is another pipe-to-shell chaining pattern, here without sudo but still allowing immediate execution of network-fetched code. In a skill meant to guide installation, such one-liners increase the chance that users run unreviewed commands verbatim, making supply-chain attacks practical.

Content

Scanner excerpt · SKILL.md (reported line 148)May include surrounding context.

npm install -g pnpm

安装 uv

curl -fsSL https://astral.sh/uv/install.sh | sh

text

**Windows (WSL2 推荐):**

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 169)May include surrounding context.

md
cd "$INSTALL_DIR"

# 3. 创建配置文件
cp .env.example .env
cp config.example.yaml config.yaml

# 4. 编辑 config.yaml,添加模型配置

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · SKILL.md (reported line 213)May include surrounding context.

md
make config-upgrade

# 3. 重建 venv
cd backend && rm -rf .venv && uv sync && cd ..

# 4. 重新安装依赖
make install

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/deer-flow-commands.md (reported line 84)May include surrounding context.

md
cd ~/deer-flow

# 2. 创建配置文件(从模板复制)
cp .env.example .env
cp config.example.yaml config.yaml

# 3. 编辑 config.yaml,添加模型配置

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

The matched rm -rf ~/deer-flow is a real destructive command that permanently removes the installation directory and all contents. In a deployment-management skill, such commands are contextually relevant but still risky because they encourage direct execution of irreversible filesystem operations.

Content

Scanner excerpt · references/deer-flow-commands.md (reported line 110)May include surrounding context.

make clean

3. 删除目录

cd ~ && rm -rf ~/deer-flow

text

### 更新步骤

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

The matched rm -rf ~/deer-flow is a real destructive command that permanently removes the installation directory and all contents. In a deployment-management skill, such commands are contextually relevant but still risky because they encourage direct execution of irreversible filesystem operations.

Content

Scanner excerpt · references/deer-flow-commands.md (reported line 110)May include surrounding context.

make clean

3. 删除目录

cd ~ && rm -rf ~/deer-flow

text

### 更新步骤

Chaining Abuse

High
Category
Tool Misuse
Confidence
91% confidence
Finding

Chaining cd ~ && rm -rf ~/deer-flow combines navigation and destruction into a single command, reducing the chance that a user pauses to verify state before deletion. In operational documentation, command chaining around destructive actions increases the likelihood of accidental misuse and makes review harder.

Content

Scanner excerpt · references/deer-flow-commands.md (reported line 110)May include surrounding context.

make clean

3. 删除目录

cd ~ && rm -rf ~/deer-flow

text

### 更新步骤

Chaining Abuse

High
Category
Tool Misuse
Confidence
89% confidence
Finding

The chained update command cd backend && rm -rf .venv && uv sync && cd .. bundles a destructive step with follow-on actions, which can obscure what is being removed and prevent users from validating necessity first. In an agent skill, compact chained commands are more likely to be run without scrutiny, raising the risk of accidental environment loss or partial update failures.

Content

Scanner excerpt · references/deer-flow-commands.md (reported line 125)May include surrounding context.

make config-upgrade

3. 重新安装依赖

cd backend && rm -rf .venv && uv sync && cd .. make install

text

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/deer-flow-commands.md (reported line 159)May include surrounding context.

统一使用 $HOME 或 ~

INSTALL_DIR="$HOME/deer-flow" CONFIG_FILE="$INSTALL_DIR/config.yaml" ENV_FILE="$INSTALL_DIR/.env" LOG_DIR="$INSTALL_DIR/logs"

text

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 139)May include surrounding context.

Linux (Ubuntu/Debian):

bash
# 安装系统依赖
sudo apt update
sudo apt install -y curl git make nginx python3.12 python3-pip

# 安装 Node.js 和 pnpm

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 140)May include surrounding context.

Linux (Ubuntu/Debian):

bash
# 安装系统依赖
sudo apt update
sudo apt install -y curl git make nginx python3.12 python3-pip

# 安装 Node.js 和 pnpm

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
95% confidence
Finding

The use of sudo -E preserves environment variables while executing a remote script as root, which broadens risk beyond ordinary sudo. Preserved environment values can influence script behavior or leak sensitive data, and combined with pipe-to-shell execution this becomes a materially dangerous privileged execution pattern.

Content

Scanner excerpt · SKILL.md (reported line 143)May include surrounding context.

md
sudo apt install -y curl git make nginx python3.12 python3-pip

# 安装 Node.js 和 pnpm
curl -fsSL https://deb.nodesource.com/setup_22.x | sudo -E bash -
sudo apt install -y nodejs
npm install -g pnpm

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
95% confidence
Finding

The use of sudo -E preserves environment variables while executing a remote script as root, which broadens risk beyond ordinary sudo. Preserved environment values can influence script behavior or leak sensitive data, and combined with pipe-to-shell execution this becomes a materially dangerous privileged execution pattern.

Content

Scanner excerpt · SKILL.md (reported line 143)May include surrounding context.

md
sudo apt install -y curl git make nginx python3.12 python3-pip

# 安装 Node.js 和 pnpm
curl -fsSL https://deb.nodesource.com/setup_22.x | sudo -E bash -
sudo apt install -y nodejs
npm install -g pnpm

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 144)May include surrounding context.

md
# 安装 Node.js 和 pnpm
curl -fsSL https://deb.nodesource.com/setup_22.x | sudo -E bash -
sudo apt install -y nodejs
npm install -g pnpm

# 安装 uv

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The uninstall flow instructs users to run rm -rf "$INSTALL_DIR" after deriving the path from a variable, but provides no confirmation, backup guidance, or sanity checks. In an agent skill context, destructive commands are more dangerous because the skill may be followed mechanically or automated, increasing the chance of accidental data loss if the variable is wrong or the user has important data under that directory.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The uninstall instructions include a recursive force-delete of the installation directory without any warning about irreversible data loss. In an agent skill context, users may copy-paste commands directly, so omission of a warning increases the risk of accidental destruction of local configuration, logs, or other files if the path is modified or misunderstood.

Content

No source excerpt is available for this finding.

External Script Fetching

Low
Category
Supply Chain
Confidence
93% confidence
Finding

curl -fsSL https://astral.sh/uv/install.sh | sh executes a remote script directly without inspection or integrity verification. In this installation-oriented skill, that pattern is more dangerous because it normalizes unaudited code execution and creates a supply-chain attack surface if the remote source is compromised.

Content

Scanner excerpt · SKILL.md (reported line 148)May include surrounding context.

npm install -g pnpm

安装 uv

curl -fsSL https://astral.sh/uv/install.sh | sh

text

**Windows (WSL2 推荐):**

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file presents all user-facing instructions in Chinese, which effectively forces a specific language for readers. There is no indication that this is a region-specific document, nor any opt-in or alternative language reference, which may violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The update instructions delete the Python virtual environment as part of a chained command but do not warn the user that local packages, caches, and environment state will be removed. While less severe than deleting arbitrary directories, this can still cause avoidable disruption and data loss for users who have custom local setup inside the environment.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.