T08 · Insecure Dependencies
- Location
references/files/monitor_install.sh:31- Finding
Downloaded Executables Are Installed Without Integrity Verification
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill has a legitimate monitoring purpose, but its installer creates persistent services with insecure defaults, weak dependency integrity, and insufficient secret and network-access protections.
Review before installing. Run it only in a controlled internal environment after adding checksum/signature verification, pinning dependencies with hashes, setting unique Grafana credentials before startup, locking down ports with firewall/auth/TLS, storing secrets with strict permissions or a secret manager, and running services under dedicated least-privilege users.
references/files/monitor_install.sh:31Downloaded Executables Are Installed Without Integrity Verification
references/files/main.yml:17Deployment Installs Mutable and Partially Unpinned Python Dependencies
references/files/main.yml:28MySQL Password and Feishu Webhook Secret Are Stored Without Enforced Restrictive Permissions
references/files/monitor_install.sh:303Monitoring Services Are Started Without Authentication or Interface Restrictions
references/files/monitor_install.sh:13Grafana Is Left With Documented Default Administrative Credentials
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
}
}
requests.post(FEISHU_WEBHOOK_URL, json=msg)
return "ok"
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
The skill advertises a comprehensive monitoring and deployment capability, but the file only describes components and example commands without showing the actual implementation artifacts. This mismatch can mislead users or higher-level agents into invoking the skill with expectations of safe, validated automation that does not actually exist, which is risky when deployment, monitoring, and alerting operations are involved.
The skill documents shell commands, network access, and use of environment variables, but does not declare any explicit tool scope such as permissions or allowed-tools. In an agent ecosystem, this can cause overbroad execution authority or make reviewers unable to verify what the skill is permitted to do, increasing the chance of unintended command execution or outbound requests.
The regex triggers are broad and can match many generic monitoring, Java, MySQL, Grafana, or Prometheus requests unrelated to this exact skill. In an agent environment, overbroad activation can cause the wrong skill to handle user requests, potentially leading to unintended shell commands, deployment guidance, or network actions in the wrong context.
Ambiguous invocation phrases like viewing JVM metrics or querying MySQL status lack boundaries on host scope, environment, or whether the skill is advisory versus operational. This increases the chance of accidental invocation in unrelated contexts and may prompt an agent to perform actions against production monitoring systems without adequate confirmation.
The documented curl command performs an outbound HTTP POST to a webhook endpoint, which is an external transmission action. While expected for alert testing, it can send data or trigger downstream notifications if used in a real environment, so the risk depends on whether the endpoint is production and whether test traffic is isolated.
curl -X POST "http://<webhook>:5000/webhook?level=warning" \
-H "Content-Type: application/json" -d '{"alerts":[]}'
journalctl -u feishu -f
The file title and all operational instructions are written in Chinese, and there is no indication that users may choose another language or that the skill is intentionally restricted to a Chinese-speaking audience. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
### Q: Prometheus 页面看不到目标
**A**:
1. 检查 Pushgateway 在线:`curl http://<pushgateway>:9091/-/healthy`
2. 检查 Prometheus target:`http://<prometheus>:9090/targets`
3. 查看 Prometheus 日志:`journalctl -u prometheus -f`
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
# ================= JCMD Histogram Collection =================
def collect_class_histo(game_dir, pid):
try:
out = subprocess.check_output(
["jcmd", str(pid), "GC.class_histogram"],
stderr=subprocess.DEVNULL, timeout=15
).decode(errors="ignore")
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
key = f"{HOSTNAME}_{game_dir}"
try:
out = subprocess.check_output(["jstat", "-gc", str(pid)]).decode().splitlines()[-1].split()
# Memory
s0u, s1u, eu = float(out[2]), float(out[3]), float(out[5])
This code pushes collected JVM and MySQL metrics to a remote Pushgateway, which is a network operation that transmits system data off-process. Although the module docstring mentions Prometheus Pushgateway, there is no confirmation prompt or stronger user-facing disclosure near the transmission path about what data is being sent.
The manifest describes a monitoring solution deployment, but this task uses a raw shell command to perform system-wide pip installation on the target host. While deployment itself is expected, invoking arbitrary shell-based package installation is a broader execution capability than the skill’s monitoring-focused purpose and is not specifically justified by the manifest text.
The playbook writes MySQL credentials in plaintext to /opt/game_monitor/env.conf, creating persistent at-rest exposure of sensitive secrets on disk. If file permissions are default or overly broad, any local user, backup process, log collection tool, or later compromise of the host could retrieve the database credentials and access MySQL.
The script writes the Feishu webhook URL directly into /opt/monitor/feishu/webhook.env, leaving a sensitive integration secret on disk without setting restrictive permissions or warning the user at the point of creation. If local users or backup systems can read this file, an attacker could abuse the webhook to exfiltrate monitoring information or send spoofed alerts.
The generated webhook service forwards hostnames, IP-derived data, service identifiers, and alert contents to an external Feishu endpoint, but the installer does not prominently disclose this outbound data flow during setup. In a production environment, this can unintentionally leak infrastructure metadata to a third-party service or to an incorrectly configured webhook destination.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
# ================= Start Services =================
systemctl daemon-reload
systemctl enable prometheus alertmanager pushgateway grafana-server feishu
systemctl start prometheus alertmanager pushgateway grafana-server feishu
echo ""
This YAML rule file contains user-facing natural-language alert text such as summaries and descriptions in Chinese only. Because the file does not offer a language choice or document a justified locale restriction, it may violate the policy against forcing a specific language without user opt-in.
No suspicious patterns detected.