Back to skill

Security audit

Claude Max Proxy Setup

Security checks for vulnerabilities and agentic risk

Overview

This skill is transparent about setting up a Claude subscription-backed local proxy, but it creates an unauthenticated local endpoint and optionally makes it persistent across sessions.

Install only after reviewing the third-party package and preferably pinning a known version. Run the proxy manually when needed instead of enabling the persistent service, keep it bound to localhost, avoid shared machines, and treat localhost:3456 as access to your Claude subscription because the proxy ignores client API keys.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T06 · System Persistence

Error
Location
SKILL.md:96
Finding

Persistent Subscription-Backed Proxy Installed as an Automatic User Service

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:96-120
Vulnerability Type: Persistent user-level service
Risk Level: High

Vulnerable Code

bash
# Create systemd user service
# Adjust paths below to match your system — find yours with:
#   which claude-max-api
#   echo $HOME
mkdir -p ~/.config/systemd/user
cat > ~/.config/systemd/user/claude-max-api-proxy.service << EOF
[Unit]
Description=Claude Max API Proxy
After=network.target

[Service]
Type=simple
ExecStart=$(which claude-max-api)
Environment=HOME=$HOME
Environment=PATH=$HOME/.npm-global/bin:/usr/local/bin:/usr/bin:/bin
Restart=on-failure
RestartSec=5

[Install]
WantedBy=default.target
EOF

systemctl --user daemon-reload
systemctl --user enable claude-max-api-proxy
systemctl --user start claude-max-api-proxy

Technical Analysis

The instructions create, enable, and immediately start a systemd user service for the proxy. The WantedBy=default.target configuration and systemctl --user enable command cause the proxy to start automatically in future user sessions. Restart=on-failure further extends its availability by restarting it after failures.

This service exposes functionality backed by the user's authenticated Claude CLI session. Although persistence is presented as optional and serves the stated proxy use case, it expands the proxy's lifetime beyond the immediate setup session and creates a durable access path to the user's subscription.

The interpolated ExecStart=$(which claude-max-api) value also permanently trusts whichever matching executable is first in PATH when the service file is generated. The principal confirmed issue, however, is the deliberate cross-session service installation.

Attack Path

  1. A user follows the optional persistent-service instructions.
  2. The Skill writes a service definition under ~/.config/systemd/user/.
  3. The service is enabled for future user sessions ...[truncated 888 chars]
Remediation
View remediation

Remediation Suggestions

  • Default to running the proxy as an explicit foreground process whose lifetime is limited to the current terminal session.

  • Remove automatic service creation and enablement from the standard setup path.

  • If persistence is required, obtain explicit informed confirmation before creating the service.

  • Require authentication on the proxy before enabling automatic startup.

  • Run the service under a dedicated, restricted account where practical.

  • Apply systemd hardening directives such as NoNewPrivileges=true, PrivateTmp=true, ProtectSystem=strict, and a narrowly scoped ReadWritePaths.

  • Resolve and validate the executable path from a trusted installation directory rather than relying on an unrestricted which lookup.

  • Document complete removal instructions, including disabling and deleting the service:

    bash
    systemctl --user disable --now claude-max-api-proxy
    rm -f ~/.config/systemd/user/claude-max-api-proxy.service
    systemctl --user daemon-reload
    

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:84
Finding

Proxy Accepts Arbitrary API Keys While Using the User's Authenticated Session

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:84-90
Vulnerability Type: Missing client authentication
Risk Level: Medium

Vulnerable Code

text
For any OpenAI-compatible client:
- Base URL: `http://localhost:3456/v1`
- API key: any non-empty string (proxy ignores it)
- Model IDs: `claude-opus-4`, `claude-sonnet-4`, `claude-haiku-4`

Technical Analysis

The documented proxy ignores the API key supplied by clients. Consequently, possession of a secret is not required to submit requests through the authenticated Claude CLI session. Loopback-only binding reduces remote exposure but does not provide client authentication or authorization.

Any process that can connect to the endpoint can impersonate an authorized client. Potential callers include malicious local applications, compromised development tools, other users where local network isolation is insufficient, and containers or virtualized workloads configured with host-network access.

The risk becomes more significant when combined with the persistent service configuration because the unauthenticated endpoint can remain available across sessions. If the proxy is accidentally rebound, forwarded, or exposed outside loopback, the same weakness may permit remote abuse.

Attack Path

  1. The victim starts the proxy while authenticated through Claude Code CLI.
  2. A malicious local process discovers or assumes the documented endpoint at localhost:3456.
  3. The process sends an OpenAI-compatible request with any arbitrary non-empty API-key value.
  4. The proxy ignores the purported credential and accepts the request.
  5. The proxy forwards attacker-controlled prompts through the victim's authenticated Claude session.
  6. The attacker consumes subscription capacity and can cause attacker-selected data to be processed under the victim's account.

Impact Assessment

Successful exploitation permits unauthorized use of the victim's subscripti ...[truncated 519 chars]

Remediation
View remediation

Remediation Suggestions

  • Generate a cryptographically random bearer token during setup and require it for every request.
  • Reject missing, malformed, or incorrect credentials rather than accepting arbitrary non-empty values.
  • Bind explicitly to 127.0.0.1 and ::1; fail closed if configuration requests a broader interface.
  • Add startup checks that warn or abort if the endpoint is reachable through a public or non-loopback interface.
  • Restrict access with operating-system firewall rules or a Unix-domain socket with restrictive file permissions.
  • Add request rate limits, concurrency limits, and audit logging that avoids recording sensitive prompt contents.
  • Rotate the proxy token after suspected exposure and provide a documented revocation procedure.
  • Do not enable persistent startup until access control is active and verified.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:52
Finding

Unpinned Third-Party Package Is Installed Globally and Immediately Executed

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:52-55
Vulnerability Type: Unsafe third-party dependency installation
Risk Level: Medium

Vulnerable Code

bash
# Review the package source first: https://github.com/atalovesyou/claude-max-api-proxy
npm install -g claude-max-api-proxy
claude-max-api   # Starts on localhost:3456 by default

Technical Analysis

The installation command does not pin an exact package version or verify a package integrity digest. It therefore installs whichever release the npm registry resolves as current at execution time. The installed binary is then executed immediately.

Global npm installation may run dependency lifecycle scripts during installation and places executable files into a user-wide or system-wide npm location, depending on local npm configuration. Reviewing a linked source repository is advisory and does not cryptographically establish that the npm artifact being installed is identical to the reviewed source.

No evidence in the audited project establishes that the named package is currently malicious. The confirmed weakness is that the instructions trust a mutable external package and its transitive dependency graph without version or integrity controls.

Attack Path

  1. The package publisher account, npm package, build pipeline, or a transitive dependency is compromised, or a later release introduces malicious behavior.
  2. A user runs the unpinned global installation command.
  3. npm resolves and downloads the compromised current release.
  4. Malicious lifecycle scripts may execute during installation, or malicious logic executes when the user runs claude-max-api.
  5. The payload runs with the privileges of the user invoking npm.
  6. It may access user files, environment variables, network resources, and Claude CLI authentication material available to that account.

Impact Assessment

A compromised dependency could execute arbitrary code wi ...[truncated 482 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin the dependency to a specifically reviewed version rather than installing the mutable latest release.

  • Verify the downloaded artifact against a documented integrity digest or signed provenance record.

  • Ensure the reviewed repository commit corresponds exactly to the published npm package.

  • Prefer a project-local installation with a committed lockfile over a global installation.

  • Audit direct and transitive dependencies before use.

  • Disable npm lifecycle scripts during initial inspection where compatible:

    bash
    npm install --ignore-scripts --save-exact claude-max-api-proxy@&lt;reviewed-version&gt;
    
  • Run the package in a sandbox or restricted account with minimal filesystem and credential access.

  • Avoid executing the package immediately after installation; inspect the resolved artifact and installed entry point first.

  • Document a trusted package publisher identity and a repeatable package-provenance verification procedure.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

The skill instructs the user to authenticate the Claude CLI and send a live test prompt through a third-party proxy workflow tied to a paid subscription. While not overtly malicious, this routes model usage through an unofficial mechanism and normalizes using a local authenticated session as a backend for other clients, which can expose account-backed model access to any local process able to reach the proxy.

Content

Scanner excerpt · SKILL.md (reported line 45)May include surrounding context.

Verify Claude Code CLI is installed and authenticated

claude --version claude --print "test" # Should return a response without errors

text

If `claude` is not authenticated, run `claude login` and complete the browser flow.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

claude-max-api # Starts on localhost:3456 by default

Verify:

curl http://localhost:3456/health

=> {"status":"ok","provider":"claude-code-cli",...}

text

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

The systemd service creation instructions establish persistence for a proxy that exposes an authenticated Claude CLI session over a local HTTP endpoint. Persistence increases attack surface and dwell time: any compromise of the host or local-access abuse can leverage the proxy repeatedly and silently.

Content

Scanner excerpt · SKILL.md (reported line 96)May include surrounding context.

4. Run as Persistent Service (Optional)

bash
# Create systemd user service
# Adjust paths below to match your system — find yours with:
#   which claude-max-api
#   echo $HOME

Session Persistence

Medium
Category
Rogue Agent
Confidence
91% confidence
Finding

Enabling the proxy as a persistent user service causes account-backed model access to survive reboots and remain continuously available on the host. If another local user, malware, or misconfiguration can access the localhost port, they can continuously consume the authenticated Claude session without needing to re-establish access manually.

Content

Scanner excerpt · SKILL.md (reported line 119)May include surrounding context.

EOF

systemctl --user daemon-reload systemctl --user enable claude-max-api-proxy systemctl --user start claude-max-api-proxy

text

Static analysis

No suspicious patterns detected.