Back to skill

Security audit

ops-maintenance

Security checks for vulnerabilities and agentic risk

Overview

This operations skill is purpose-aligned, but its production command execution and credential handling are broader and less protected than users are told.

Install only if you are comfortable giving this skill administrative visibility into local and remote systems. Use a dedicated low-privilege SSH account, avoid password auth, pin or verify host keys outside the skill, do not run fleet exec against production without reviewing the exact command, avoid putting alert tokens or SMTP passwords in the saved config, and treat configuration snapshots and audit logs as sensitive files.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (6)

T09 · Insecure Skill Coding Practices

Error
Location
skills/ops-maintenance/src/utils/network-diagnostics.ts:76
Finding

Local Command Injection Through Network Diagnostic Arguments

Content
View full analysis
{ try { const cmd = `ping -c ${count} -W 5 ${host}` const validation = validateCommand(cmd) const { stdout } = await execAsync(cmd, { timeout: this.timeout }) const alive = !stdout.includes('100% packet loss') ``` The variable `validation` is calculated but never checked. Other methods construct similar shell commands using `host`, `server`, `maxHops`, `count`, and `port` before passing them to `execAsync`. The public wrappers pass arguments directly to these methods: ```ts export async function networkPing(host: string, count: number = 4): Promise { const diag = getNetworkDiagnostics() const result = await diag.ping(host, count) return diag.formatPingResult(result) } ``` ### Technical Analysis Node.js `child_process.exec` executes its input through a shell. The implementation concatenates externally supplied diagnostic parameters into a command string without strict syntax validation or shell escaping. Although `ping()` calls `validateCommand`, it ignores the returned `safe` value. DNS, traceroute, MTR, and port-check paths shown during the audit execute dynamically constructed commands without effective validation. A timeout limits execution duration but does not prevent command injection. The injected command runs with the same operating-system identity and privileges as the Skill process. ### Attack Path 1. An attacker or untrusted caller supplies a crafted value to a public operation such as `networkPing`, `networkDns`, `networkTraceroute`, `networkMtr`, or `networkCheckPort` ...[truncated 1295 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
skills/ops-maintenance/src/utils/command-validator.ts:29
Finding

Overbroad Command Allowlist Enables Secret Disclosure and File Exfiltration

Content
View full analysis
{ const validation = validateCommand(command) if (!validation.safe) { throw new Error(`Security validation failed: ${validation.reason}`) } const servers = tags ? await Promise.all(tags.map(getServersByTag)).then(arr => arr.flat()) : await loadServers() const pool = getSSHPool() for (let i = 0; i < servers.length; i += 5) { const batch = servers.slice(i, i + 5) await Promise.all(batch.map(async (config) => { const result = await pool.executeCommand(config, command) results.push({ server: config.name || config.host, output: result.stdout || result.stderr || '(no output)' }) })) } return results } ``` ### Technical Analysis The validator is described as a read-only command allowlist, but several patterns grant substantially broader authority: - `env` discloses the complete remote process environment. - Unrestricted `cat`, `head`, and `tail` allow reading arbitrary files accessible to the SSH account. - `wget` accepts arbitrary options and destinations. It is not limited to a safe read- ...[truncated 1838 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
skills/ops-maintenance/src/utils/service-manager.ts:178
Finding

Command Injection in Docker and System Service Inspection Helpers

Content
View full analysis
{ try { const cmd = `docker inspect ${nameOrId}` const output = await this.runCmd(cmd) const data = JSON.parse(output)[0] const networks = data.NetworkSettings?.Networks || {} ``` The local execution helper invokes a shell: ```ts private async runCmd(cmd: string): Promise { if (this.remoteExec) { return this.remoteExec(cmd) } const { stdout } = await execAsync(cmd, { timeout: this.timeout }) return stdout } ``` Other affected command constructions include: ```ts const cmd = `docker stats --no-stream --format "..." ${container}` const cmd = `docker logs --tail ${lines} ${sinceArg} ${nameOrId} 2>&1` const cmd = `systemctl status ${serviceName} 2>&1 || true` const cmd = `journalctl -u ${serviceName} -n ${lines} --no-pager ${sinceArg} -o short-iso 2>&1` ``` ### Technical Analysis Container identifiers, service names, line counts, and time expressions are inserted into shell commands without escaping or strict validation. When no remote executor is supplied, `runCmd` passes the resulting command to `execAsync`, which uses a shell. The public wrappers `dockerStats`, `dockerInspect`, `dockerLogs`, `serviceStatus`, `serviceBatchStatus`, and `serviceLogs` make these methods reachable from the Skill API. The presence of `2>&1` and `|| true` in generated commands confirms that shell interpretation is intentional. Consequently, an attacker-controlled identifier can alter the command structure rather than remaining a single Docker or systemd argument. ### Attack Path 1. A caller invokes a D ...[truncated 1198 chars]
Remediation
View remediation
&1` and `|| true`; capture stdout, stderr, and exit codes through the child-process API. 7. Apply identical validation in local and remote execution modes. 8. Add regression tests for separators, substitutions, newlines, option injection, and malformed identifiers. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
skills/ops-maintenance/src/utils/alert-manager.ts:224
Finding

SMTP and Webhook Credentials Persisted in Plaintext Without Restrictive File Modes

Content
View full analysis
) { this.configDir = join(process.env.HOME || '~', '.config/ops-maintenance') this.alertFile = join(this.configDir, 'alerts.json') this.configFile = join(this.configDir, 'alert-config.json') if (!existsSync(this.configDir)) { mkdirSync(this.configDir, { recursive: true }) } const loadedConfig = this.loadConfig() this.rules = config?.rules || loadedConfig.rules || DEFAULT_ALERT_RULES this.notify = config?.notify || loadedConfig.notify || {} } saveConfig(): void { const config: AlertManagerConfig = { rules: this.rules, notify: this.notify, repeatInterval: this.repeatInterval, silencePeriod: this.silencePeriod, } writeFileSync(this.configFile, JSON.stringify(config, null, 2)) } ``` The `notify` object can include SMTP usernames and passwords, webhook URLs containing tokens, and custom authorization headers. ### Technical Analysis Notification configuration is serialized directly to `~/.config/ops-maintenance/alert-config.json`. No encryption, keychain integration, explicit `0600` file mode, or `0700` directory mode is applied. The resulting permissions depend on the runtime umask and existing parent-directory permissions. On permissively configured systems, other local users or processes may read the file. This also conflicts with the project's broader claim that sensitive configuration is automatically encrypted: the password encryption helper covers server passwords, not alert credentials. ### Attack Path 1. A user configures email or webhook notifications through the CLI. 2. The CLI calls `updateNotifyConfig`, which stores the supplied configuration in `this.notify`. 3. `saveConfig` serializes the complete notification configu ...[truncated 932 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
skills/ops-maintenance/src/utils/ssh-pool.ts:65
Finding

SSH Connections Do Not Verify Server Host Keys

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
skills/ops-maintenance/src/utils/crypto.ts:29
Finding

First-Run Failure in Encrypted Credential Storage Initialization

Content
View full analysis
{ const keyPath = getKeyPath() const configDir = getConfigDir() if (!existsSync(configDir)) { await writeFile(configDir, '') } if (existsSync(keyPath)) { ``` The secure server configuration functions depend on this routine: ```ts export async function saveServersSecurely(servers: any[]): Promise { const configDir = getConfigDir() const configPath = join(configDir, 'servers.json') const encryptedServers = await Promise.all( servers.map(async (server) => { const encrypted = { ...server } if (server.password && !isEncrypted(server.password)) { encrypted.password = await encrypt(server.password) } return encrypted }) ) await writeFile(configPath, JSON.stringify(encryptedServers, null, 2), { mode: 0o600 }) } ``` ### Technical Analysis When the configuration directory is absent, the code calls `writeFile(configDir, '')` instead of creating a directory. This either: - Creates a regular file where a directory is expected, or - Fails because a parent path is absent. Subsequent attempts to create `.key` or `servers.json` beneath that path then fail. This breaks the documented automatic password-encryption workflow on a clean installation. Although the defect does not directly disclose a credential, it undermines a security control that users are told will protect stored SSH passwords. ### Attack Path 1. The Skill runs under a user account with no existing `~/.config/ops-maintenance` directory. 2. A server configuration containing a password is saved. 3. `saveServersSecurely` calls `encrypt`. 4. `encrypt` calls `getOrGenerateKey`. 5. The code attempts to create the directory path using `writeFile`. 6. Key creation or configur ...[truncated 784 chars]
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (342)

Intent-Code Divergence

Critical
Category
Not specified by scanner
Confidence
99% confidence
Finding

The document claims only safe read-only commands are allowed, yet the exposed interface includes generic remote exec capability, directly contradicting that assurance. This is dangerous because users and orchestrators may trust the stated restriction while the interface still permits broad command execution, including possible bypass of intended safeguards.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The documented exec capability enables generic local or remote shell execution across hosts or groups, which is materially riskier than passive monitoring and can be abused for destructive actions, lateral movement, or data exfiltration if invoked with unsafe input or insufficient authorization controls. In an operations skill, this context makes the issue more dangerous because the skill is explicitly positioned to access production infrastructure and server inventories.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documented exec capability enables generic local or remote shell execution across hosts or groups, which is materially riskier than passive monitoring and can be abused for destructive actions, lateral movement, or data exfiltration if invoked with unsafe input or insufficient authorization controls. In an operations skill, this context makes the issue more dangerous because the skill is explicitly positioned to access production infrastructure and server inventories.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documented exec capability enables generic local or remote shell execution across hosts or groups, which is materially riskier than passive monitoring and can be abused for destructive actions, lateral movement, or data exfiltration if invoked with unsafe input or insufficient authorization controls. In an operations skill, this context makes the issue more dangerous because the skill is explicitly positioned to access production infrastructure and server inventories.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documented exec capability enables generic local or remote shell execution across hosts or groups, which is materially riskier than passive monitoring and can be abused for destructive actions, lateral movement, or data exfiltration if invoked with unsafe input or insufficient authorization controls. In an operations skill, this context makes the issue more dangerous because the skill is explicitly positioned to access production infrastructure and server inventories.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The documented exec capability enables generic local or remote shell execution across hosts or groups, which is materially riskier than passive monitoring and can be abused for destructive actions, lateral movement, or data exfiltration if invoked with unsafe input or insufficient authorization controls. In an operations skill, this context makes the issue more dangerous because the skill is explicitly positioned to access production infrastructure and server inventories.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documented exec capability enables generic local or remote shell execution across hosts or groups, which is materially riskier than passive monitoring and can be abused for destructive actions, lateral movement, or data exfiltration if invoked with unsafe input or insufficient authorization controls. In an operations skill, this context makes the issue more dangerous because the skill is explicitly positioned to access production infrastructure and server inventories.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documented exec capability enables generic local or remote shell execution across hosts or groups, which is materially riskier than passive monitoring and can be abused for destructive actions, lateral movement, or data exfiltration if invoked with unsafe input or insufficient authorization controls. In an operations skill, this context makes the issue more dangerous because the skill is explicitly positioned to access production infrastructure and server inventories.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The documented exec capability enables generic local or remote shell execution across hosts or groups, which is materially riskier than passive monitoring and can be abused for destructive actions, lateral movement, or data exfiltration if invoked with unsafe input or insufficient authorization controls. In an operations skill, this context makes the issue more dangerous because the skill is explicitly positioned to access production infrastructure and server inventories.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The documented exec capability enables generic local or remote shell execution across hosts or groups, which is materially riskier than passive monitoring and can be abused for destructive actions, lateral movement, or data exfiltration if invoked with unsafe input or insufficient authorization controls. In an operations skill, this context makes the issue more dangerous because the skill is explicitly positioned to access production infrastructure and server inventories.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The documented exec capability enables generic local or remote shell execution across hosts or groups, which is materially riskier than passive monitoring and can be abused for destructive actions, lateral movement, or data exfiltration if invoked with unsafe input or insufficient authorization controls. In an operations skill, this context makes the issue more dangerous because the skill is explicitly positioned to access production infrastructure and server inventories.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documented exec "..." @production and exec "..." all expose arbitrary command execution across multiple servers, creating a high-risk primitive for fleet-wide damage, credential harvesting, persistence installation, or bulk service disruption. The cluster-operations context amplifies impact because a single misuse can affect many production hosts at once.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 255)May include surrounding context.

md
npm test -- test/core.test.ts

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 352)May include surrounding context.

md
4. 更新`container.ts`注册依赖

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

The code remotely executes cat /etc/shadow to enumerate accounts, which touches one of the most sensitive authentication files on Unix systems. Even though it only extracts usernames and appears intended for password-expiry auditing, reading /etc/shadow requires elevated privileges and expands credential-access capability; if this feature is misused, over-privileged, or insufficiently access-controlled elsewhere, it can facilitate account reconnaissance and increase blast radius on compromised admin paths.

Content

Scanner excerpt · dist/core/usecases/PasswordCheckUseCase.js (reported line 48)May include surrounding context.

js
*/
    async checkServerPasswords(server) {
        // 1. 获取有密码的用户列表
        const usersOutput = await this.ssh.execute(server, 'cat /etc/shadow 2>/dev/null | cut -d: -f1 | grep -v "^[$!*]$" | head -20');
        const users = usersOutput.trim().split('\n').filter(u => u.trim());
        if (users.length === 0) {
            return [];

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 142)May include surrounding context.

md
* 凭据存储方案(按优先级):
 * 1. 环境变量: OPS_CRED_<HOST>={user:password} 或 OPS_CRED_<HOST>_KEY 文件路径
 * 2. 配置文件附加字段(不推荐生产使用)
 * 3. SSH 默认密钥 (~/.ssh/id_rsa)
 */
export declare class ConfigManagerCredentialsProvider implements ICredentialsProvider {
    private configManager;

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 104)May include surrounding context.

md
* 凭据存储方案(按优先级):
 * 1. 环境变量: OPS_CRED_<HOST>={user:password} 或 OPS_CRED_<HOST>_KEY 文件路径
 * 2. 配置文件附加字段(不推荐生产使用)
 * 3. SSH 默认密钥 (~/.ssh/id_rsa)
 */
export declare class ConfigManagerCredentialsProvider implements ICredentialsProvider {
    private configManager;

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · dist/infrastructure/repositories/CredentialsRepository.d.ts (reported line 16)May include surrounding context.

ts
* 凭据存储方案(按优先级):
 * 1. 环境变量: OPS_CRED_<HOST>={user:password} 或 OPS_CRED_<HOST>_KEY 文件路径
 * 2. 配置文件附加字段(不推荐生产使用)
 * 3. SSH 默认密钥 (~/.ssh/id_rsa)
 */
export declare class ConfigManagerCredentialsProvider implements ICredentialsProvider {
    private configManager;

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · dist/infrastructure/repositories/CredentialsRepository.js (reported line 18)May include surrounding context.

js
* 凭据存储方案(按优先级):
 * 1. 环境变量: OPS_CRED_<HOST>={user:password} 或 OPS_CRED_<HOST>_KEY 文件路径
 * 2. 配置文件附加字段(不推荐生产使用)
 * 3. SSH 默认密钥 (~/.ssh/id_rsa)
 */
export declare class ConfigManagerCredentialsProvider implements ICredentialsProvider {
    private configManager;

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · doc/ARCHITECTURE.md (reported line 96)May include surrounding context.

md
* 凭据存储方案(按优先级):
 * 1. 环境变量: OPS_CRED_<HOST>={user:password} 或 OPS_CRED_<HOST>_KEY 文件路径
 * 2. 配置文件附加字段(不推荐生产使用)
 * 3. SSH 默认密钥 (~/.ssh/id_rsa)
 */
export declare class ConfigManagerCredentialsProvider implements ICredentialsProvider {
    private configManager;

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · examples/remote-example.ts (reported line 44)May include surrounding context.

ts
* 凭据存储方案(按优先级):
 * 1. 环境变量: OPS_CRED_<HOST>={user:password} 或 OPS_CRED_<HOST>_KEY 文件路径
 * 2. 配置文件附加字段(不推荐生产使用)
 * 3. SSH 默认密钥 (~/.ssh/id_rsa)
 */
export declare class ConfigManagerCredentialsProvider implements ICredentialsProvider {
    private configManager;

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skills/ops-maintenance/SKILL.md (reported line 268)May include surrounding context.

md
* 凭据存储方案(按优先级):
 * 1. 环境变量: OPS_CRED_<HOST>={user:password} 或 OPS_CRED_<HOST>_KEY 文件路径
 * 2. 配置文件附加字段(不推荐生产使用)
 * 3. SSH 默认密钥 (~/.ssh/id_rsa)
 */
export declare class ConfigManagerCredentialsProvider implements ICredentialsProvider {
    private configManager;

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skills/ops-maintenance/SKILL.md (reported line 318)May include surrounding context.

md
* 凭据存储方案(按优先级):
 * 1. 环境变量: OPS_CRED_<HOST>={user:password} 或 OPS_CRED_<HOST>_KEY 文件路径
 * 2. 配置文件附加字段(不推荐生产使用)
 * 3. SSH 默认密钥 (~/.ssh/id_rsa)
 */
export declare class ConfigManagerCredentialsProvider implements ICredentialsProvider {
    private configManager;

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · src-new/infrastructure/repositories/CredentialsRepository.ts (reported line 19)May include surrounding context.

ts
* 凭据存储方案(按优先级):
 * 1. 环境变量: OPS_CRED_<HOST>={user:password} 或 OPS_CRED_<HOST>_KEY 文件路径
 * 2. 配置文件附加字段(不推荐生产使用)
 * 3. SSH 默认密钥 (~/.ssh/id_rsa)
 */
export declare class ConfigManagerCredentialsProvider implements ICredentialsProvider {
    private configManager;

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 52)May include surrounding context.

md
*
     * 示例:
     * - OPS_CRED_10_119_120_143="salt:Giten!#202501Tab*&"
     * - OPS_KEY_10_119_120_143=/home/user/.ssh/id_rsa
     */
    private getFromEnvironment;
    /**

Static analysis

Detected: suspicious.dangerous_exec, suspicious.exposed_secret_literal, suspicious.insecure_tls_verification

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
run-dev.js:61

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:119

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
test/security.test.ts:23

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
skills/ops-maintenance/src/utils/ssl-monitor.ts:185