Back to skill

Security audit

TencentCloud Websocket Checker

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real WebSocket diagnostic tool, but its installer and scripts allow high-impact shell and network actions without enough safeguards.

Install only if you are comfortable auditing shell scripts and running network diagnostics from this machine. Do not run the sudo installer blindly, avoid the macOS remote Homebrew bootstrap path, run checks only against endpoints you own or are authorized to test, avoid private/internal targets unless that is intentional, and validate test rounds as a simple 1-10 integer before use.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T03 · Remote Payload Retrieval and Execution

Error
Location
install_dependencies.sh:185
Finding

Mutable Remote Homebrew Installer Is Downloaded and Executed Without Verification

Content
View full analysis

Vulnerability Details

File Location: install_dependencies.sh:185-190
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

bash
# Check whether Homebrew is installed
if ! command -v brew &>/dev/null; then
    echo -e "  ${YELLOW}Homebrew is not installed; installing it now...${NC}"
    /bin/bash -c "$(curl -fsSL https://raw.githubusercontent.com/Homebrew/install/HEAD/install.sh)"
fi

Technical Analysis

The macOS dependency-installation path retrieves the current HEAD version of Homebrew's installation script and passes the response directly to Bash. The URL belongs to the recognized Homebrew GitHub repository, but it references a mutable branch rather than an immutable revision.

No checksum, cryptographic signature, pinned commit, or local review step is used. Consequently, the effective code executed by this Skill can change after the Skill package has been audited. TLS protects the transport connection but does not guarantee that future upstream content remains identical or uncompromised.

This behavior exceeds the minimum privileges and capabilities required for WebSocket latency measurement. The core checker only needs existing command-line utilities; it does not inherently require immediate execution of remotely supplied shell code.

Attack Path

  1. A user follows the documented dependency-installation workflow on macOS.
  2. The script determines that brew is unavailable.
  3. The script downloads the current upstream installer from the mutable HEAD reference.
  4. Bash executes the response without integrity verification or inspection.
  5. If the upstream repository, maintainer account, delivery path, or retrieved content is compromised, attacker-controlled commands execute with the installer user's privileges.
  6. The upstream installer may request or use elevated permissions during installation, increasing the potential impact depending on user ap ...[truncated 467 chars]
Remediation
View remediation

Remediation Suggestions

  • Remove the download-to-shell pattern from the dependency installer.
  • Prefer instructing users to install Homebrew independently from its official, reviewed installation procedure.
  • If automated retrieval is essential, pin the installer to an immutable reviewed commit rather than HEAD.
  • Download the file separately, verify a trusted cryptographic digest or signature, and only then execute it.
  • Display the source URL, expected digest, and intended changes before execution.
  • Require explicit user confirmation before running third-party installation code.
  • Avoid running the overall installer with elevated privileges on macOS; elevate only individual operations that demonstrably require it.

T09 · Insecure Skill Coding Practices

Error
Location
ws_check.sh:155
Finding

Unvalidated Round Count Reaches Bash Arithmetic Evaluation

Content
View full analysis

Vulnerability Details

File Location: ws_check.sh:155-180, 424; also present in utils/report_generator.sh:28,60 and forwarded by utils/batch_check.sh:38,78
Vulnerability Type: Bash arithmetic-expression injection
Risk Level: High

bash
# ws_check.sh
PARSED_URL="${positional_args[0]}"
PARSED_ROUNDS="${positional_args[1]:-$DEFAULT_ROUNDS}"
bash
local url="$PARSED_URL"
local rounds="$PARSED_ROUNDS"

for ((round = 1; round <= rounds; round++)); do
    echo -ne "  Round ${round}/${rounds}..."
bash
# utils/report_generator.sh
URL="$1"
ROUNDS="${2:-3}"
FORMAT="${3:-csv}"

for ((round = 1; round <= ROUNDS; round++)); do
    timing_output=$(curl -s -o /dev/null \
        -w "dns:%{time_namelookup} tcp:%{time_connect} tls:%{time_appconnect} transfer:%{time_starttransfer} total:%{time_total} http_code:%{http_code}" \
        -H 'Upgrade: websocket' \
        -H 'Connection: Upgrade' \
        -H 'Sec-WebSocket-Key: dGhlIHNhbXBsZSBub25jZQ==' \
        -H 'Sec-WebSocket-Version: 13' \
        --max-time 15 \
        "$full_url" 2>/dev/null)
bash
# utils/batch_check.sh
ROUNDS="${2:-3}"

if bash "$WS_CHECK" "$url" "$ROUNDS" 2>&1; then
    SUCCESS=$((SUCCESS + 1))
fi

Technical Analysis

The round-count argument is accepted as an arbitrary string and later referenced in Bash arithmetic contexts. Bash arithmetic operands are expressions rather than strictly parsed decimal integers. Variable values may therefore be recursively interpreted as arithmetic syntax, including crafted array-subscript expressions capable of triggering shell evaluation behavior.

The scripts do not enforce the documented range of 1 through 10. Even when an input does not achieve command execution, malformed, negative, or extremely large expressions can cause errors, excessive network traffic, or prolonged execution.

The batch wrapper safely quotes the argu ...[truncated 1325 chars]

Remediation
View remediation

Remediation Suggestions

  • Validate round counts immediately at every public entry point:
bash
if [[ ! "$ROUNDS" =~ ^([1-9]|10)$ ]]; then
    echo "Error: rounds must be an integer from 1 to 10" >&2
    exit 1
fi
  • Convert only the validated value to a base-10 integer:
bash
ROUNDS=$((10#$ROUNDS))
  • Apply equivalent validation to PARSED_ROUNDS in ws_check.sh.
  • Validate in batch_check.sh before forwarding the value and independently revalidate it in ws_check.sh.
  • Reject extra positional arguments rather than silently ignoring them.
  • Add regression tests containing arithmetic operators, array syntax, command-substitution syntax, negative values, zero, decimals, whitespace, and values greater than 10.
  • Consider enforcing a total execution deadline in addition to the per-request timeout.

other

Warning
Location
ws_check.sh:252
Finding

Arbitrary Targets Permit Internal-Network Probing

Content
View full analysis

Vulnerability Details

File Location: ws_check.sh:252-283; also present in utils/report_generator.sh:49-72
Vulnerability Type: Server-side request forgery and internal-network reconnaissance
Risk Level: Medium

bash
run_single_measurement() {
    local proto="$1"
    local domain="$2"
    local port="$3"
    local path="$4"

    local curl_proto
    if [ "$proto" = "wss" ]; then
        curl_proto="https"
    else
        curl_proto="http"
    fi
    local full_url="${curl_proto}://${domain}:${port}${path}"

    local timing_output
    timing_output=$(curl -s -o /dev/null \
        -w "dns:%{time_namelookup} tcp:%{time_connect} tls:%{time_appconnect} transfer:%{time_starttransfer} total:%{time_total} http_code:%{http_code}" \
        -H 'Upgrade: websocket' \
        -H 'Connection: Upgrade' \
        -H 'Sec-WebSocket-Key: dGhlIHNhbXBsZSBub25jZQ==' \
        -H 'Sec-WebSocket-Version: 13' \
        --max-time 15 \
        "$full_url" 2>/dev/null)

    if [ $? -ne 0 ] && [ -z "$timing_output" ]; then
        echo "ERROR"
        return 1
    fi

    echo "$timing_output"
}

Technical Analysis

The checker accepts an arbitrary hostname or IP address, port, and path, then initiates DNS and HTTP/HTTPS connections from the machine executing the Skill. It does not reject loopback, private, link-local, multicast, IPv6-local, or cloud metadata addresses.

Although response bodies are discarded, the script reports DNS results, connection success, HTTP status, and timing data. These outputs form a reachability and service-enumeration oracle. When the Skill runs on an Agent host with access to protected networks, a remote requester may use it to probe resources that are not directly reachable from the requester's own environment.

Network access is necessary for the declared diagnostic purpose, but unrestricted access to all host-reachable destinations exceeds l ...[truncated 1230 chars]

Remediation
View remediation

Remediation Suggestions

  • Resolve the destination before connecting and reject all non-public address ranges by default.
  • Block IPv4 loopback, RFC1918, link-local, carrier-grade NAT, multicast, reserved, and cloud metadata ranges.
  • Apply equivalent checks to IPv6 loopback, unique-local, link-local, multicast, mapped IPv4, and reserved ranges.
  • Revalidate every resolved address immediately before connection to reduce DNS-rebinding risk.
  • Use an explicit destination allowlist in managed or hosted Agent deployments.
  • Require clear user confirmation before connecting to private or otherwise non-public targets.
  • Restrict allowed destination ports to expected WebSocket ports unless the user explicitly authorizes an exception.
  • Run the checker in a sandbox with outbound network policy that prevents access to management and metadata networks.
  • Log the requester, destination, resolved address, port, and authorization decision for auditability.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (45)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 40)May include surrounding context.

md
### 1. 主检测脚本 `ws_check.sh`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 47)May include surrounding context.

md
### 1. 主检测脚本 `ws_check.sh`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 48)May include surrounding context.

md
### 1. 主检测脚本 `ws_check.sh`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 51)May include surrounding context.

md
### 1. 主检测脚本 `ws_check.sh`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 52)May include surrounding context.

md
### 1. 主检测脚本 `ws_check.sh`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 55)May include surrounding context.

md
### 1. 主检测脚本 `ws_check.sh`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 127)May include surrounding context.

md
### 1. 主检测脚本 `ws_check.sh`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 132)May include surrounding context.

md
### 1. 主检测脚本 `ws_check.sh`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 133)May include surrounding context.

md
### 1. 主检测脚本 `ws_check.sh`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 144)May include surrounding context.

md
### 1. 主检测脚本 `ws_check.sh`

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

This duplicate finding flags the same insecure example: curl -k disables server certificate verification. In the context of WebSocket/TLS troubleshooting, this can mislead users into treating failed validation as acceptable, undermining transport security and masking real certificate problems.

Content

Scanner excerpt · docs/TROUBLESHOOTING.md (reported line 116)May include surrounding context.

验证 SSL 证书

openssl s_client -connect your-domain.com:443 -servername your-domain.com

如果证书有问题,可临时使用 curl -k(不推荐生产使用)

curl -k -I https://your-domain.com/

text

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

This duplicate finding flags the same insecure example: curl -k disables server certificate verification. In the context of WebSocket/TLS troubleshooting, this can mislead users into treating failed validation as acceptable, undermining transport security and masking real certificate problems.

Content

Scanner excerpt · docs/TROUBLESHOOTING.md (reported line 116)May include surrounding context.

验证 SSL 证书

openssl s_client -connect your-domain.com:443 -servername your-domain.com

如果证书有问题,可临时使用 curl -k(不推荐生产使用)

curl -k -I https://your-domain.com/

text

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill clearly instructs use of shell scripts, dependency installation, and network diagnostics, but it does not declare any tool scope or allowed-tools constraints. In an agent environment, missing explicit permission boundaries can let the model invoke shell/network-capable actions more broadly than intended, increasing the risk of unintended command execution or network probing.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger description contains broad catch-all language like activating even when the user merely mentions related topics, which can cause the skill to fire in contexts where the user did not ask for network diagnostics. Over-broad triggering is dangerous because it may lead the agent to suggest or initiate probing behavior, shell usage, or dependency installation unexpectedly.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
91% confidence
Finding

The skill recommends running an installation script via 'sudo bash', which encourages privileged execution of a script from the skill package without any integrity verification or least-privilege safeguards. If the script is modified, malicious, or simply flawed, it could make system-wide changes, install unwanted packages, or compromise the host with root privileges.

Content

Scanner excerpt · SKILL.md (reported line 114)May include surrounding context.

自动检测操作系统(CentOS/Ubuntu/macOS)并安装所需工具:

bash
sudo bash install_dependencies.sh

所需依赖:curl、dig(bind-utils/dnsutils)、awk(gawk)、sed

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file presents all usage instructions and operational guidance only in Chinese, which can violate a language/locale policy when no user opt-in or alternative locale is offered. The file does not state that the skill is region-specific or intentionally limited to Chinese-speaking users.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · docs/EXAMPLES.md (reported line 138)May include surrounding context.

bash
# 编辑 crontab
crontab -e

# 每小时执行一次检测,结果追加到日志文件
0 * * * * /path/to/ws_check.sh wss://your-server.com/ws 3 >> /var/log/ws_latency.log 2>&1

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README instructs users to run a privileged installation script with sudo, which can make system-wide package changes or execute arbitrary installer logic as root without any warning, review step, or description of side effects. In skill ecosystems, users may copy-paste setup commands directly, so undocumented privileged execution meaningfully increases the risk of unintended system modification or privilege misuse.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
95% confidence
Finding

The explicit sudo invocation encourages executing install_dependencies.sh with root privileges, granting the script full control over the host if it contains unsafe commands or is modified. This is more dangerous in an agent skill context because users may trust packaged setup instructions and run them without auditing the script contents first.

Content

Scanner excerpt · docs/README.md (reported line 37)May include surrounding context.

bash
# 自动检测并安装所需工具
sudo bash install_dependencies.sh

2. 赋予执行权限

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · docs/TROUBLESHOOTING.md (reported line 26)May include surrounding context.

解决方案:

bash
# CentOS / RHEL
sudo yum install -y bind-utils

# Ubuntu / Debian
sudo apt install -y dnsutils

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · docs/TROUBLESHOOTING.md (reported line 49)May include surrounding context.

解决方案:

bash
# CentOS / RHEL
sudo yum install -y bind-utils

# Ubuntu / Debian
sudo apt install -y dnsutils

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · docs/TROUBLESHOOTING.md (reported line 65)May include surrounding context.

解决方案:

bash
# CentOS / RHEL
sudo yum install -y bind-utils

# Ubuntu / Debian
sudo apt install -y dnsutils

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · docs/TROUBLESHOOTING.md (reported line 96)May include surrounding context.

解决方案:

bash
# CentOS / RHEL
sudo yum install -y bind-utils

# Ubuntu / Debian
sudo apt install -y dnsutils

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · docs/TROUBLESHOOTING.md (reported line 29)May include surrounding context.

md
# WebSocket 连接延迟检测工具 - 依赖安装脚本
# 功能:自动检测并安装 ws_check.sh 运行所需的全部依赖
# 支持:CentOS/RHEL、Ubuntu/Debian、macOS
# 用法:sudo bash install_dependencies.sh
# ============================================================

set -euo pipefail

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · docs/TROUBLESHOOTING.md (reported line 46)May include surrounding context.

md
# WebSocket 连接延迟检测工具 - 依赖安装脚本
# 功能:自动检测并安装 ws_check.sh 运行所需的全部依赖
# 支持:CentOS/RHEL、Ubuntu/Debian、macOS
# 用法:sudo bash install_dependencies.sh
# ============================================================

set -euo pipefail

Static analysis

No suspicious patterns detected.