Back to skill

Security audit

Windows 服务器运维工具箱

Security checks for vulnerabilities and agentic risk

Overview

This Windows admin skill has a legitimate purpose, but its safety labels understate powerful actions such as persistent scheduled tasks, fleet-wide remote commands, credential handling, webhook egress, and destructive cleanup.

Review carefully before installing. Use only in a controlled admin environment, avoid production cleanup/remote-command/monitoring modules unless you have explicit approvals, and do not store privileged credentials or webhook secrets through the provided snippets without stronger scoping, cleanup, and least-privilege controls.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (6)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
references/modules/module-31-轻量常驻监控.md:108
Finding

Highest-privilege SYSTEM scheduled task executes a user-profile PowerShell script

Content
View full analysis
Remediation
View remediation

T06 · System Persistence

Error
Location
references/modules/module-28-性能基线-&-趋势分析.md:33
Finding

Read-only performance analysis silently registers a persistent scheduled task

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/modules/module-30-远程多服务器管理.md:118
Finding

Unvalidated commands are executed with administrator credentials across every registered server

Content
View full analysis
&1 [PSCustomObject]@{ Server = $env:COMPUTERNAME Status = "Success" Output = $output | Out-String } } -ArgumentList $command -ErrorAction Stop } ``` ### Technical Analysis `Invoke-Expression` interprets an arbitrary string as PowerShell code. The command is supplied directly from interactive input and is not parsed against an allowlist, constrained to read-only operations, or represented through typed parameters. The workflow fans the same command out to every registered server using the supplied credentials. Merely displaying the command is not an independent confirmation gate. The code therefore does not enforce the Skill's stated requirement that modifying operations wait for explicit confirmation. Because the command can include pipelines, script blocks, downloads, encoded payloads, service operations, account changes, or destructive filesystem commands, the effective capability is unrestricted remote PowerShell execution. ### Attack Path 1. An attacker, compromised prompt source, or incorrect AI-generated instruction persuades the operator to paste a malicious command. 2. The module loads all server names from `servers.json`. 3. The operator supplies shared administrative credentials. 4. `Invoke-Command` establishes sessions to all sel ...[truncated 635 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/modules/module-30-远程多服务器管理.md:44
Finding

Administrative password is exposed as a process command-line argument

Content
View full analysis
$null } ``` ### Technical Analysis `Get-Credential` initially stores the password as a `SecureString`, but `GetNetworkCredential().Password` converts it to plaintext. That plaintext is then included in the `cmdkey.exe` command line. Process command lines may be visible to local process-inspection tools, endpoint telemetry, administrative users, debugging infrastructure, or command-line auditing systems. The secret is also persisted in Windows Credential Manager without a separate explanation of its lifetime or an implemented credential-removal path. The target name uses the `TERMSRV/` namespace even though the module subsequently performs WinRM operations. This can create ambiguous credential scope and may not provide the expected security boundary. ### Attack Path 1. An administrator enters a privileged password into the credential prompt. 2. The module converts the protected password to plaintext. 3. The plaintext value is inserted into the `cmdkey.exe` process arguments. 4. A local monitoring process, privileged user, EDR telemetry collector, or process-inspection tool captures the command line. 5. The captured credential is used to access the target server or other systems where the password is reused. ### Impact Assessment Exposure grants the privileges associated with the entered account. Because the module is intended for remote server administration, the account may have local administrator, server ad ...[truncated 195 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/modules/module-27-自动化修复向导.md:369
Finding

Temporary-file cleanup permanently deletes all unrelated Recycle Bin contents

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/modules/module-33-告警推送.md:21
Finding

Webhook bearer secret is stored in plaintext and the destination is not validated

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (64)

YARA rule 'reverse_shell': Reverse shell patterns in scripts or source code [malware]

Critical
Category
YARA Match
Confidence
85% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · references/modules/module-20-SSL-证书过期检测.md (reported line 122)May include surrounding context.

}

text



### 20.3 远程域名证书探测(本地无证书的站点)




```powershell
# 将下方域名替换为你需要检测的站点
$domains = @('www.baidu.com', 'www.taobao.com')  # 示例,替换为你的域名

Write-Host "════════ 远程域名 SSL 证书检测 ════════"
foreach ($domain in $domains) {
    try {
        $tcpClient = New-Object System.Net.Sockets.TcpClient($domain, 443)
        $sslStream  = New-Object System.Net.Security.SslStream($tcpClient.GetStream(), $false, { $true })
        $sslStream.AuthenticateAsClient($domain)
        $cert = $sslStream.RemoteCertificate
        $expiry = [DateTime]::Parse($cert.GetExpirationDateString())
        $daysLeft = ($expiry - (Get-Date)).Days
        $status = if ($daysLeft -lt 0) { '❌ 已过期' }
                   elseif ($daysLeft -lt 30) { '⚠️ 即将过期' }
                   else { '✅ 正常' }
        Write-Host "  $domain → 到期: $($expi

YARA rule 'reverse_shell': Reverse shell patterns in scripts or source code [malware]

Critical
Category
YARA Match
Confidence
85% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · references/modules/module-27-自动化修复向导.md (reported line 421)May include surrounding context.

}

text



### 20.3 远程域名证书探测(本地无证书的站点)




```powershell
# 将下方域名替换为你需要检测的站点
$domains = @('www.baidu.com', 'www.taobao.com')  # 示例,替换为你的域名

Write-Host "════════ 远程域名 SSL 证书检测 ════════"
foreach ($domain in $domains) {
    try {
        $tcpClient = New-Object System.Net.Sockets.TcpClient($domain, 443)
        $sslStream  = New-Object System.Net.Security.SslStream($tcpClient.GetStream(), $false, { $true })
        $sslStream.AuthenticateAsClient($domain)
        $cert = $sslStream.RemoteCertificate
        $expiry = [DateTime]::Parse($cert.GetExpirationDateString())
        $daysLeft = ($expiry - (Get-Date)).Days
        $status = if ($daysLeft -lt 0) { '❌ 已过期' }
                   elseif ($daysLeft -lt 30) { '⚠️ 即将过期' }
                   else { '✅ 正常' }
        Write-Host "  $domain → 到期: $($expi

Description-Behavior Mismatch

Critical
Category
Not specified by scanner
Confidence
99% confidence
Finding

The disk-cleanup flow performs irreversible deletion of temp files and empties the recycle bin, directly contradicting the parent claim that the tool is read-only and will not delete files. In an agent setting, this can cause unintended data loss because operators may invoke the skill believing it is safe from deletion.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The module advertises the toolbox as '只读分析+安全确认,绝不误删文件', yet this file defines active repair workflows that stop services, reset network state, and delete files. This mismatch is dangerous because users or higher-level agents may grant trust and permissions under a read-only assumption, leading to unexpected system changes.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The module explicitly claims all operations are read-only, but the code creates directories, writes CSV files, and registers a scheduled task that persists for 7 days. This mismatch can mislead operators or higher-level agents into granting execution under a lower-risk assumption, while the code actually performs persistent state changes and ongoing data collection.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The safety statement and the implementation are directly contradictory: the module says it will not modify system configuration, yet it installs a scheduled task and writes output files. Such deceptive or inaccurate safety labeling undermines trust boundaries and may cause unauthorized persistence on systems where only non-mutating diagnostics were expected.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The module explicitly claims all operations are read-only, but later includes report-generation code that creates a directory and writes a Markdown file under the user's profile. This mismatch can mislead users or orchestration systems into granting trust or permissions they would not otherwise allow, undermining safety guarantees even if the write is only local output.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The manifest marks the skill as readonly, yet the code creates a directory and writes a file to disk during normal report generation. In agent environments, mode flags may be used as trust boundaries; violating them can bypass policy expectations, cause unintended persistence, and enable follow-on abuse if other components rely on the readonly declaration.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This module advertises read-only/safe-confirm behavior, but section 30.2 enables arbitrary command execution across multiple remote servers via Invoke-Command and Invoke-Expression. That creates a direct capability for state-changing administration, destructive actions, or lateral movement, and the misleading safety claims increase the chance that an agent or operator will invoke it under false assumptions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation states that many administrative changes are unsupported and that the tool is read-only, yet this module explicitly supports remote management workflows that can alter state on many systems. This mismatch is dangerous because users and calling agents may trust the policy text while the actual module exposes mechanisms for credential storage, remoting, and arbitrary command execution.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The module is labeled mode: readonly, but it creates files under the user profile and installs a recurring scheduled task running as SYSTEM with ExecutionPolicy Bypass. That is a significant privilege and persistence mismatch: users or higher-level agents may trust the metadata and invoke it expecting non-mutating behavior, while it actually establishes privileged long-term execution.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill metadata and description claim the toolbox runs completely offline, but this module explicitly sends alert contents to external enterprise webhook endpoints using Invoke-RestMethod. That mismatch can mislead operators into enabling the skill in restricted or sensitive environments, causing unintended network egress and disclosure of hostnames, metrics, threshold values, and operational recommendations to third-party services.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The display name, descriptions, quick-start prompts, and operational guidance are all written in Chinese, including an instruction that users can 'directly speak to AI' using Chinese examples. The file does not offer multilingual usage, an opt-in language preference, or a documented reason that the skill must be Chinese-only, which can violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill claims '完全免费离线运行/无需联网', yet later advertises remote multi-server management and webhook-based alert delivery. This mismatch is security-relevant because users may deploy the skill in restricted or sensitive environments assuming there is no outbound communication capability, when in fact network-capable features exist.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The quick-start phrases are broad natural-language prompts such as checking disks, IIS, or cleanup, which increases the chance of accidental invocation by an agent or user in ordinary conversation. In a skill that includes cleanup, service inspection, and potentially repair workflows, unintended triggering can lead to unnecessary data collection or progression toward impactful actions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly presents itself as '只读诊断' and '不修改任何文件', but the logging function creates directories, appends to a log file, rotates logs, and deletes old log files. This is a real integrity/trust issue because users and calling agents may rely on the documented safety boundary when deciding whether to invoke the skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The description does not prominently warn users that the skill may persist telemetry/logs locally and may send alerts externally via webhooks. Missing disclosure undermines informed consent and can cause inappropriate use in regulated or isolated environments where persistence and egress are tightly controlled.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The description explicitly presents the skill as a Windows Server CIS baseline in Chinese, and all user-facing content items are also written only in Chinese. This creates a language/locale constraint without any opt-in, alternative language option, or documented region-specific justification in the file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The standard name and description are presented only in Chinese, and the file gives no indication that the locale is optional or that the skill is region-specific. Under the language/locale policy, forcing a specific language without user opt-in or clear documented justification is a policy concern.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger phrases are broad, natural-language requests that are likely to appear in normal support conversations. In an automation context, this can cause unintended invocation of a cleanup workflow that leads to scanning or deletion actions when the user intended a discussion, diagnosis, or narrower operation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The module promises preview-first cleanup with explicit user confirmation, but the second PowerShell block contains immediately runnable deletion logic with only a comment as a safeguard. In an agent or copy-paste workflow, comments do not enforce policy, so the destructive action could run without a verified confirmation step or without a trustworthy preview context.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The module documentation claims broader 'safe cleanup' coverage across multiple sensitive temporary locations, but the preview script only enumerates the current user's %TEMP% directory. This mismatch can mislead an operator or downstream agent into believing all listed paths were reviewed before cleanup, increasing the chance of deleting files from unreviewed locations if the deletion phase is adapted or invoked with a broader file set.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrase '看看各个目录的空间占用' is broad and could activate the module in contexts where the user did not explicitly intend this specific disk-usage report. Overly permissive activation boundaries can cause unintended execution of filesystem enumeration logic, which may expose directory size information from sensitive paths such as C:\Users, ProgramData, or IIS-related folders.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

All user-facing descriptions, triggers, warnings, and instructions are presented in Chinese, and the file does not indicate that the skill is intended only for Chinese-speaking users or provide an opt-in language choice. That can conflict with organizational language/locale policy requiring user choice or explicit justification.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The module metadata and description claim 'readonly' and '只读分析+安全确认', but the documented workflow includes stopping a Windows service, deleting update cache files, and restarting the service. This mismatch can cause an orchestrator or user to trust the module as non-mutating when it actually contains destructive operational steps, increasing the risk of unintended state changes on production systems.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.