Back to skill

Security audit

Catfee Ssh

Security checks for vulnerabilities and agentic risk

Overview

This SSH operations skill is coherent, but it handles server passwords and remote admin commands with weak safeguards that users should review carefully before installing.

Install only if you are comfortable giving the agent SSH credentials and remote command authority. Prefer SSH keys or a secure secret mechanism, verify server host fingerprints before connecting, use least-privilege accounts, avoid root where possible, and approve any restart, reload, file modification, or sudo command explicitly. Preinstall and review a pinned Posh-SSH version instead of letting the skill install the latest module automatically.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Error
Location
SKILL.md:15
Finding

Unpinned Runtime Installation of a Third-Party PowerShell Module

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:23
Finding

Automatic Acceptance of Unverified SSH Host Keys

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (8)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README instructs users to send SSH passwords directly to the agent in chat, but it does not warn that secrets entered into conversational interfaces may be logged, retained, forwarded to tools, or exposed to other components handling prompts and transcripts. In a skill whose core function is remote administrative access, this omission materially increases the chance of credential disclosure and subsequent compromise of the target server.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill uses New-SSHSession ... -AcceptKey, which disables meaningful host key verification by automatically trusting whatever key the remote host presents on first contact. This enables man-in-the-middle attacks, credential interception, and connection to spoofed hosts, which is especially dangerous because the skill explicitly handles username/password authentication to remote servers.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill includes examples of privileged remote modification commands such as sudo nginx -s reload and sudo systemctl restart docker without requiring explicit confirmation or warning about production impact. In an operations skill this is contextually expected, but it still increases the risk of accidental service disruption or misuse because the examples normalize making live changes on remote systems.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 105)May include surrounding context.

执行需要sudo权限的操作:

powershell
Invoke-SSHCommand -SessionId $session.SessionId -Command "sudo nginx -s reload"
Invoke-SSHCommand -SessionId $session.SessionId -Command "sudo systemctl restart docker"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 106)May include surrounding context.

执行需要sudo权限的操作:

powershell
Invoke-SSHCommand -SessionId $session.SessionId -Command "sudo nginx -s reload"
Invoke-SSHCommand -SessionId $session.SessionId -Command "sudo systemctl restart docker"

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The primary skill description is presented in Chinese without offering the user a language or locale choice. This can violate language/locale policy when a skill effectively forces one language without explicit opt-in or documented regional justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The natural-language description is written to operate in Chinese and does not indicate any user option for language or locale preference. Under the stated policy, language-specific behavior should either offer opt-in/choice or clearly justify the locale restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The package description is written only in Chinese ("SSH远程服务器密码连接技能...") and does not indicate any user choice of language or locale. This can constitute a language/locale policy issue because the skill presents itself in a single language without opt-in or documented regional justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.