Back to skill

Security audit

System Monitor Pro

Security checks for vulnerabilities and agentic risk

Overview

This monitoring skill is mostly purpose-aligned, but its optional remote SSH mode is implemented insecurely enough that users should review it before installing.

Install only if you are comfortable with a monitoring skill that can run local system-status commands and, when used with --remote, SSH into another host. Avoid remote mode until the command construction is fixed to use argument arrays or strict validation, and host-key checking is restored. Consider narrowing the triggers before enabling it in an agent environment, and do not add the suggested HEARTBEAT.md recurring entry unless you want periodic automatic monitoring.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
monitor.js:8
Finding

OS Command Injection Through the Unvalidated Remote Host Argument

Content
View full analysis

Vulnerability Details

File Location: monitor.js, lines 8-24
Vulnerability Type: OS command injection
Risk Level: High

Vulnerable Code:

javascript
const remoteHost = args.includes('--remote') ? args[args.indexOf('--remote') + 1] : null;
javascript
function run(cmd, timeout = 8000) {
  try { return execSync(cmd, { timeout, encoding: 'utf8', stdio: ['pipe','pipe','pipe'] }).trim(); }
  catch { return null; }
}

function remoteRun(cmd) {
  const escaped = cmd.replace(/"/g, '\\"');
  return run(`ssh -o ConnectTimeout=3 -o StrictHostKeyChecking=no ${remoteHost} "${escaped}"`);
}

Technical Analysis

The value of remoteHost is read directly from the command-line arguments and interpolated into a command string passed to execSync. Because execSync executes the string through a shell, shell metacharacters contained in remoteHost are interpreted as command syntax.

The script only escapes double quotes in the remote command stored in cmd. It performs no validation or shell escaping of remoteHost, which occupies an unquoted position in the generated SSH command. Consequently, an attacker who can influence the --remote argument can terminate or modify the intended SSH command and cause an additional local command to run.

The broad exception handler does not mitigate this vulnerability. An injected command can execute before execSync returns or throws, while the error is then silently discarded.

Attack Path

  1. An attacker gains control over, or persuades an agent or user to supply, the value following --remote.
  2. The attacker supplies a value containing shell control syntax rather than a valid user@host target.
  3. remoteRun() inserts that value directly into the SSH command string.
  4. run() passes the constructed string to execSync.
  5. The local shell interprets the injected syntax and executes the attacker-controlled command with the privileges o ...[truncated 700 chars]
Remediation
View remediation

Remediation Suggestions

  • Replace shell-based execSync use with execFileSync or spawnSync, passing the executable and each argument separately. For example, invoke ssh with an argument array rather than constructing a shell command string.
  • Validate remoteHost against a strict allowlist grammar supporting only the required hostname, IP address, and optional username formats.
  • Reject absent values, whitespace, control characters, shell metacharacters, and values beginning with a hyphen.
  • Use an explicit end-of-options marker where supported to prevent a target from being interpreted as an SSH option.
  • Do not rely on manual quote replacement as a substitute for eliminating shell interpretation.
  • Return a clear error for invalid input instead of silently converting execution failures to null.
  • Add automated tests covering malicious metacharacters, option injection, missing --remote values, IPv4/IPv6 targets, and valid user@host targets.

T09 · Insecure Skill Coding Practices

Warning
Location
monitor.js:23
Finding

SSH Server Identity Verification Is Disabled

Content
View full analysis

Vulnerability Details

File Location: monitor.js, line 23
Vulnerability Type: Insecure SSH host-key verification
Risk Level: Medium

Vulnerable Code:

javascript
return run(`ssh -o ConnectTimeout=3 -o StrictHostKeyChecking=no ${remoteHost} "${escaped}"`);

Technical Analysis

The SSH invocation explicitly sets StrictHostKeyChecking=no. This prevents the client from reliably requiring prior trust in the remote server's host key and may permit an unrecognized host key to be accepted automatically, depending on the remaining SSH client configuration.

SSH host-key validation is the mechanism that authenticates the server before credentials or commands are sent. Disabling strict verification weakens that authentication boundary and exposes remote monitoring sessions to server impersonation, DNS manipulation, routing attacks, or other man-in-the-middle conditions.

Attack Path

  1. A user or agent invokes the skill to monitor a remote machine.
  2. An attacker capable of influencing DNS, routing, or the network path redirects the SSH connection to an attacker-controlled server.
  3. The SSH client encounters an unknown or otherwise untrusted host key.
  4. Because strict host-key checking is disabled, the connection may proceed without requiring trustworthy verification of the server identity.
  5. The attacker receives the monitoring commands and can return fabricated hostname, resource, Gateway, and cron output.
  6. If the selected SSH authentication configuration exposes reusable authentication material to the session, the consequences may extend beyond monitoring-data manipulation; the exact credential risk depends on the user's SSH configuration and authentication method.

Impact Assessment

The direct impact is loss of remote-server authenticity and monitoring integrity. An attacker could conceal resource exhaustion, report a false Gateway state, falsify cron health, or otherwise mislead opera ...[truncated 291 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove StrictHostKeyChecking=no and use the SSH client's normal host-key verification behavior.
  • Pre-provision trusted host keys in a dedicated known_hosts file for unattended monitoring.
  • Configure UserKnownHostsFile to reference that controlled file and require strict verification.
  • Pin host keys through a trusted deployment process rather than retrieving them over the same untrusted connection being authenticated.
  • Treat host-key mismatches as hard failures and report them clearly to the user or monitoring system.
  • Use separate, least-privileged SSH credentials for monitoring and restrict the remote account to the commands required for system-status collection.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill metadata and documentation present this as a monitoring utility, but it also advertises remote SSH monitoring of arbitrary hosts via --remote user@host. Remote access is a materially higher-risk capability than local status display, and understating or incompletely declaring that behavior can mislead users into invoking network-reaching actions they did not expect. The mismatch is worsened by references to specific remote hosts and periodic automation guidance, which could normalize unattended remote connections.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger set includes generic phrases like monitor, dashboard, and health check, which are common in ordinary conversation and can cause unintended activation. In a skill that may launch scripts and optionally initiate SSH-based remote monitoring, accidental triggering increases the chance of unexpected system inspection or network access without deliberate user intent.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Remote monitoring is implemented by constructing shell commands and executing them over SSH for any requested host, which is broader than a narrowly scoped telemetry mechanism. Because the remote host value is inserted into the SSH command string and the feature executes arbitrary shell commands remotely, this expands the attack surface substantially and can lead to local command injection or unsafe remote execution if the host argument is influenced by untrusted input.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The SSH invocation disables host key verification with StrictHostKeyChecking=no, which removes protection against man-in-the-middle attacks and silent redirection to an attacker-controlled host. In a monitoring skill that may be used for operational decisions, trusting unauthenticated remote endpoints can expose sensitive system status and allow deceptive output to be presented as legitimate.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill performs SSH-based remote command execution without clearly warning the user that host key checks are bypassed, preventing informed consent about the security tradeoff. This is especially risky because the dangerous behavior is hidden behind a benign 'monitoring' feature and may cause operators to trust insecure remote connections they would otherwise reject.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Multiple user-facing status and alert strings are hardcoded in Chinese, and the skill does not offer a language selection or document that it is intentionally limited to a Chinese-speaking audience. This can violate language or locale policy when users are not given an opt-in or alternative locale.

Content

No source excerpt is available for this finding.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
78% confidence
Finding

The Chinese trigger 监控 is extremely short and broadly used, making unintended matches likely. By itself this is a low-severity issue, but in the context of a monitoring skill with optional SSH functionality, even accidental activation can expose local or remote system information unexpectedly.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
monitor.js:17