T08 · Insecure Dependencies
- Location
SKILL.md:15- Finding
Unpinned Runtime Installation of a Third-Party PowerShell Module
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This SSH operations skill is coherent, but it handles server passwords and remote admin commands with weak safeguards that users should review carefully before installing.
Install only if you are comfortable giving the agent SSH credentials and remote command authority. Prefer SSH keys or a secure secret mechanism, verify server host fingerprints before connecting, use least-privilege accounts, avoid root where possible, and approve any restart, reload, file modification, or sudo command explicitly. Preinstall and review a pinned Posh-SSH version instead of letting the skill install the latest module automatically.
SKILL.md:15Unpinned Runtime Installation of a Third-Party PowerShell Module
SKILL.md:23Automatic Acceptance of Unverified SSH Host Keys
The README instructs users to send SSH passwords directly to the agent in chat, but it does not warn that secrets entered into conversational interfaces may be logged, retained, forwarded to tools, or exposed to other components handling prompts and transcripts. In a skill whose core function is remote administrative access, this omission materially increases the chance of credential disclosure and subsequent compromise of the target server.
The skill uses New-SSHSession ... -AcceptKey, which disables meaningful host key verification by automatically trusting whatever key the remote host presents on first contact. This enables man-in-the-middle attacks, credential interception, and connection to spoofed hosts, which is especially dangerous because the skill explicitly handles username/password authentication to remote servers.
The skill includes examples of privileged remote modification commands such as sudo nginx -s reload and sudo systemctl restart docker without requiring explicit confirmation or warning about production impact. In an operations skill this is contextually expected, but it still increases the risk of accidental service disruption or misuse because the examples normalize making live changes on remote systems.
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
执行需要sudo权限的操作:
Invoke-SSHCommand -SessionId $session.SessionId -Command "sudo nginx -s reload"
Invoke-SSHCommand -SessionId $session.SessionId -Command "sudo systemctl restart docker"
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
执行需要sudo权限的操作:
Invoke-SSHCommand -SessionId $session.SessionId -Command "sudo nginx -s reload"
Invoke-SSHCommand -SessionId $session.SessionId -Command "sudo systemctl restart docker"
The primary skill description is presented in Chinese without offering the user a language or locale choice. This can violate language/locale policy when a skill effectively forces one language without explicit opt-in or documented regional justification.
The natural-language description is written to operate in Chinese and does not indicate any user option for language or locale preference. Under the stated policy, language-specific behavior should either offer opt-in/choice or clearly justify the locale restriction.
The package description is written only in Chinese ("SSH远程服务器密码连接技能...") and does not indicate any user choice of language or locale. This can constitute a language/locale policy issue because the skill presents itself in a single language without opt-in or documented regional justification.
No suspicious patterns detected.