Back to skill

Security audit

sshx

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent SSH administration helper, but it gives agents broad remote admin, secret, and database mutation powers with documented safety-bypass options that should be manually reviewed before use.

Install only if you intentionally want an agent to operate remote servers and databases through sshx. Limit it to trusted workspaces and named hosts, prefer dry-run and plan binding before mutations, keep audits enabled, avoid --force, --no-safety-check, --password-get, and env-file credential discovery unless a human explicitly approves the specific operation, and do not grant access to production hosts or keyrings broader than the task requires.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (43)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 151)May include surrounding context.

When you need to verify what sshx would do before touching a server, pass --dry-run --json. It prints a local execution plan and does not connect, execute, read keyring secrets, mutate known_hosts, or write settings.

bash
sshx -h=prod-web --dry-run --json "sudo systemctl restart nginx"

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 292)May include surrounding context.

When you need to verify what sshx would do before touching a server, pass --dry-run --json. It prints a local execution plan and does not connect, execute, read keyring secrets, mutate known_hosts, or write settings.

bash
sshx -h=prod-web --dry-run --json "sudo systemctl restart nginx"

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 304)May include surrounding context.

When you need to verify what sshx would do before touching a server, pass --dry-run --json. It prints a local execution plan and does not connect, execute, read keyring secrets, mutate known_hosts, or write settings.

bash
sshx -h=prod-web --dry-run --json "sudo systemctl restart nginx"

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 577)May include surrounding context.

When you need to verify what sshx would do before touching a server, pass --dry-run --json. It prints a local execution plan and does not connect, execute, read keyring secrets, mutate known_hosts, or write settings.

bash
sshx -h=prod-web --dry-run --json "sudo systemctl restart nginx"

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 632)May include surrounding context.

When you need to verify what sshx would do before touching a server, pass --dry-run --json. It prints a local execution plan and does not connect, execute, read keyring secrets, mutate known_hosts, or write settings.

bash
sshx -h=prod-web --dry-run --json "sudo systemctl restart nginx"

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 309)May include surrounding context.

md
## Safety checks (block destructive commands)

By default sshx blocks obviously destructive commands (`rm -rf /`, `mkfs`, `dd`,
fork bombs, `curl | sh`, edits to `/etc/passwd|shadow`, shutdown/reboot). A blocked
command never touches the network and reports `error_kind: "blocked"`.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 323)May include surrounding context.

md
## Safety checks (block destructive commands)

By default sshx blocks obviously destructive commands (`rm -rf /`, `mkfs`, `dd`,
fork bombs, `curl | sh`, edits to `/etc/passwd|shadow`, shutdown/reboot). A blocked
command never touches the network and reports `error_kind: "blocked"`.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 309)May include surrounding context.

md
## Safety checks (block destructive commands)

By default sshx blocks obviously destructive commands (`rm -rf /`, `mkfs`, `dd`,
fork bombs, `curl | sh`, edits to `/etc/passwd|shadow`, shutdown/reboot). A blocked
command never touches the network and reports `error_kind: "blocked"`.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 310)May include surrounding context.

md
## Safety checks (block destructive commands)

By default sshx blocks obviously destructive commands (`rm -rf /`, `mkfs`, `dd`,
fork bombs, `curl | sh`, edits to `/etc/passwd|shadow`, shutdown/reboot). A blocked
command never touches the network and reports `error_kind: "blocked"`.

Direct database client execution is also blocked in run/script mode: any

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 310)May include surrounding context.

md
## Safety checks (block destructive commands)

By default sshx blocks obviously destructive commands (`rm -rf /`, `mkfs`, `dd`,
fork bombs, `curl | sh`, edits to `/etc/passwd|shadow`, shutdown/reboot). A blocked
command never touches the network and reports `error_kind: "blocked"`.

Direct database client execution is also blocked in run/script mode: any

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 323)May include surrounding context.

statement through sshx sql instead.

bash
sshx -h=host "sudo rm -rf /tmp/*"   # allowed
sshx -h=host "sudo rm -rf /"        # BLOCKED

# Bypass only when you are certain (use sparingly):

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 323)May include surrounding context.

statement through sshx sql instead.

bash
sshx -h=host "sudo rm -rf /tmp/*"   # allowed
sshx -h=host "sudo rm -rf /"        # BLOCKED

# Bypass only when you are certain (use sparingly):

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

This match highlights the same underlying issue: the skill exposes force-bypass semantics adjacent to destructive command examples. When an agent has remote command execution, documented control bypasses significantly increase the probability and severity of harmful parameter use.

Content

Scanner excerpt · SKILL.md (reported line 324)May include surrounding context.

bash
sshx -h=host "sudo rm -rf /tmp/*"   # allowed
sshx -h=host "sudo rm -rf /"        # BLOCKED

# Bypass only when you are certain (use sparingly):
sshx -h=host --force "sudo reboot"        # -f bypasses the check for this run

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
86% confidence
Finding

This match highlights the same underlying issue: the skill exposes force-bypass semantics adjacent to destructive command examples. When an agent has remote command execution, documented control bypasses significantly increase the probability and severity of harmful parameter use.

Content

Scanner excerpt · SKILL.md (reported line 324)May include surrounding context.

bash
sshx -h=host "sudo rm -rf /tmp/*"   # allowed
sshx -h=host "sudo rm -rf /"        # BLOCKED

# Bypass only when you are certain (use sparingly):
sshx -h=host --force "sudo reboot"        # -f bypasses the check for this run

Credential Access

High
Category
Privilege Escalation
Confidence
81% confidence
Finding

The skill supports extracting database credentials from remote deployment .env files, which are commonly sensitive secret stores. While intended for convenience, this expands the skill's ability to harvest credentials from application configuration and increases blast radius if the agent is misused.

Content

Scanner excerpt · SKILL.md (reported line 435)May include surrounding context.

"UPDATE users SET active=false WHERE id=42"

Credentials from a deployment env file, cached for 1 hour.

sshx sql -h=prod --docker=pg-prod --db-cred-from=env-file:/opt/app/.env
--cred-cache=1h --json "SELECT count(*) FROM orders"

text

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

/etc/shadow is a highly sensitive credential store, and the skill text permits overriding protections with force flags. Even with warnings, exposing this operation in agent-facing guidance creates substantial risk of credential compromise or authentication backdooring on managed systems.

Content

Scanner excerpt · SKILL.md (reported line 515)May include surrounding context.

md
- Backups default to `~/.sshx/file-backups/`. `--no-backup` requires `--force`.
- `--sudo` stages the payload over SFTP, then installs with a privileged
  stdin script. Use it when the SSH user cannot write the target.
- `/etc/passwd`, `/etc/shadow`, and `/etc/sudoers` require
  `--force --bypass-reason=`.
- JSON fields to branch on: `success`, `change_state`, `executed`, `verified`,
  `verification`, `completion` (legacy `changed` / `created` remain),

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

/etc/shadow is a highly sensitive credential store, and the skill text permits overriding protections with force flags. Even with warnings, exposing this operation in agent-facing guidance creates substantial risk of credential compromise or authentication backdooring on managed systems.

Content

Scanner excerpt · SKILL.md (reported line 515)May include surrounding context.

md
- Backups default to `~/.sshx/file-backups/`. `--no-backup` requires `--force`.
- `--sudo` stages the payload over SFTP, then installs with a privileged
  stdin script. Use it when the SSH user cannot write the target.
- `/etc/passwd`, `/etc/shadow`, and `/etc/sudoers` require
  `--force --bypass-reason=`.
- JSON fields to branch on: `success`, `change_state`, `executed`, `verified`,
  `verification`, `completion` (legacy `changed` / `created` remain),

Credential Access

High
Category
Privilege Escalation
Confidence
72% confidence
Finding

The skill exposes --password-get=master, which is an explicit secret retrieval primitive. Even though it is limited to OS keyring and piped use, agent-accessible plaintext secret retrieval materially increases the risk of credential exfiltration or accidental disclosure.

Content

Scanner excerpt · SKILL.md (reported line 579)May include surrounding context.

sshx --password-check=server-A # exists? (alias: --password-exists) sshx --password-list # stored keys (vault) or common keys (keyring) sshx --password-delete=server-A # delete (alias: --password-del)

OS keyring only, and only when piped: sshx --password-get=master

text

## Authentication & host-key behavior

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: sshx
description: Operate remote servers with the `sshx` CLI — inspect hosts, dissect remote logs with `sshx text`, run commands over SSH, transfer files over SFTP, apply a single remote file, manage named hosts, store SSH/sudo passwords in the OS keyring or local vault, and run guarded SQL. Use when the user wants structured host discovery, log/exception triage, remote command execution, safe config file changes, upload/download, host management, or safe production database changes. Prefer `--json`. Do not wrap grep/journalctl in `sshx run` when `sshx text` fits.
---

# sshx

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 27)May include surrounding context.

md
---
name: sshx
description: Operate remote servers with the `sshx` CLI — inspect hosts, dissect remote logs with `sshx text`, run commands over SSH, transfer files over SFTP, apply a single remote file, manage named hosts, store SSH/sudo passwords in the OS keyring or local vault, and run guarded SQL. Use when the user wants structured host discovery, log/exception triage, remote command execution, safe config file changes, upload/download, host management, or safe production database changes. Prefer `--json`. Do not wrap grep/journalctl in `sshx run` when `sshx text` fits.
---

# sshx

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 293)May include surrounding context.

md
---
name: sshx
description: Operate remote servers with the `sshx` CLI — inspect hosts, dissect remote logs with `sshx text`, run commands over SSH, transfer files over SFTP, apply a single remote file, manage named hosts, store SSH/sudo passwords in the OS keyring or local vault, and run guarded SQL. Use when the user wants structured host discovery, log/exception triage, remote command execution, safe config file changes, upload/download, host management, or safe production database changes. Prefer `--json`. Do not wrap grep/journalctl in `sshx run` when `sshx text` fits.
---

# sshx

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 294)May include surrounding context.

md
---
name: sshx
description: Operate remote servers with the `sshx` CLI — inspect hosts, dissect remote logs with `sshx text`, run commands over SSH, transfer files over SFTP, apply a single remote file, manage named hosts, store SSH/sudo passwords in the OS keyring or local vault, and run guarded SQL. Use when the user wants structured host discovery, log/exception triage, remote command execution, safe config file changes, upload/download, host management, or safe production database changes. Prefer `--json`. Do not wrap grep/journalctl in `sshx run` when `sshx text` fits.
---

# sshx

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 315)May include surrounding context.

md
---
name: sshx
description: Operate remote servers with the `sshx` CLI — inspect hosts, dissect remote logs with `sshx text`, run commands over SSH, transfer files over SFTP, apply a single remote file, manage named hosts, store SSH/sudo passwords in the OS keyring or local vault, and run guarded SQL. Use when the user wants structured host discovery, log/exception triage, remote command execution, safe config file changes, upload/download, host management, or safe production database changes. Prefer `--json`. Do not wrap grep/journalctl in `sshx run` when `sshx text` fits.
---

# sshx

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 316)May include surrounding context.

md
---
name: sshx
description: Operate remote servers with the `sshx` CLI — inspect hosts, dissect remote logs with `sshx text`, run commands over SSH, transfer files over SFTP, apply a single remote file, manage named hosts, store SSH/sudo passwords in the OS keyring or local vault, and run guarded SQL. Use when the user wants structured host discovery, log/exception triage, remote command execution, safe config file changes, upload/download, host management, or safe production database changes. Prefer `--json`. Do not wrap grep/journalctl in `sshx run` when `sshx text` fits.
---

# sshx

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 490)May include surrounding context.

md
---
name: sshx
description: Operate remote servers with the `sshx` CLI — inspect hosts, dissect remote logs with `sshx text`, run commands over SSH, transfer files over SFTP, apply a single remote file, manage named hosts, store SSH/sudo passwords in the OS keyring or local vault, and run guarded SQL. Use when the user wants structured host discovery, log/exception triage, remote command execution, safe config file changes, upload/download, host management, or safe production database changes. Prefer `--json`. Do not wrap grep/journalctl in `sshx run` when `sshx text` fits.
---

# sshx

Static analysis

No suspicious patterns detected.