Back to skill

Security audit

tunelo

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent tunneling purpose, but it should be reviewed because it installs through an unverified remote shell script and can publicly expose local files or services with limited safeguards.

Install only after you trust the publisher and have reviewed or verified the installer separately. Use this skill only for content you intentionally want reachable from the internet, prefer `--private` for demos and APIs, and share a minimal prepared directory rather than project roots, home folders, credentials, or internal admin services.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:22
Finding

Unverified Remote Installation Script Executed Directly by Shell

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 22
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Vulnerable Code:

bash
curl -fsSL https://tunelo.net/install.sh | sh

Technical Analysis

The installation command retrieves a mutable shell script from an external server and immediately passes its contents to sh. The project does not pin the installer to an immutable version, validate a cryptographic signature or checksum, or provide the installer source for inspection.

Although HTTPS protects the connection in transit, it does not protect against compromise of the hosting server, domain or deployment credentials, nor against the script being intentionally changed after this Skill has been reviewed. Consequently, the effective code executed by this instruction cannot be determined from the audited project.

Piping the response directly into a shell also prevents normal inspection before execution. The documentation states that the resulting binary may be installed at /usr/local/bin/tunelo, indicating that the external installer may perform a system-wide installation. The installer and binary were not included in the project, so their precise behavior, integrity, persistence mechanisms, and data handling could not be audited.

Attack Path

  1. An Agent or user follows the installation instruction in SKILL.md.
  2. curl requests the current content of https://tunelo.net/install.sh.
  3. The external hosting infrastructure, domain, or deployment account is compromised, or the remotely hosted script is otherwise modified.
  4. The server returns attacker-controlled shell commands.
  5. The pipe sends those commands directly to sh without integrity verification or review.
  6. The commands execute with all permissions available to the invoking account.
  7. If the Agent or user invoked the installation in an elevated context, the payload may modify system-wide fil ...[truncated 970 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the direct curl | sh installation pattern.
  2. Publish versioned release artifacts through a reputable package registry or an immutable release URL.
  3. Pin the documentation to an exact release version rather than retrieving a mutable installer.
  4. Publish SHA-256 checksums through an independently protected channel and verify the downloaded artifact before execution.
  5. Prefer cryptographic signature verification using a documented public signing key.
  6. Download the installer to a local file first, verify its integrity, and make it available for inspection before running it.
  7. Include the installer source and relevant build instructions in the auditable project.
  8. Install into a user-owned directory by default and avoid requesting administrative privileges unless a specific system-wide installation is explicitly required.
  9. Document every filesystem, network, and privilege change performed by the installer.
  10. For subsequent tunnel usage, require explicit confirmation of the exact directory or port being exposed and default public tunnels to authenticated access such as --private.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

This line fetches an external script from the internet and executes it directly, creating a high-risk supply-chain and remote-code-execution path. Because the skill is meant for agent use, it may normalize unsafe automated installation practices where no human reviews the downloaded code first.

Content

Scanner excerpt · SKILL.md (reported line 22)May include surrounding context.

Install

bash
curl -fsSL https://tunelo.net/install.sh | sh

If tunelo is not found after install, the binary is at /usr/local/bin/tunelo.

Chaining Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

The | sh construct is a command-chaining pattern that turns network-delivered content into immediate shell execution, removing any opportunity for validation or review. This sharply increases the blast radius of compromise because any malicious response becomes arbitrary command execution on the machine running the skill.

Content

Scanner excerpt · SKILL.md (reported line 22)May include surrounding context.

Install

bash
curl -fsSL https://tunelo.net/install.sh | sh

If tunelo is not found after install, the binary is at /usr/local/bin/tunelo.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is explicitly designed to expose localhost services and local files to the public internet, but it does not prominently warn about the privacy and security consequences of doing so. In an agent context, this increases the risk that sensitive local content, admin interfaces, development tools, or internal APIs are shared externally without informed user consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The installation instruction downloads and immediately executes a remote shell script, which gives the remote server full code execution on the host at install time. If the distribution endpoint, DNS, TLS termination, or upstream infrastructure is compromised, users or agents would run attacker-controlled code without review.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The examples encourage serving directories publicly but do not instruct users to verify that the directory excludes secrets, credentials, private documents, source control metadata, or other sensitive files. In an agent workflow, broad directory sharing can easily expose more content than intended, especially when the agent selects . or user home subdirectories.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.