Back to skill

Security audit

SSH Handoff

Security checks for vulnerabilities and agentic risk

Overview

This skill openly creates temporary shared terminal access, but its implementation has unsafe token and temporary-file handling that could expose or compromise a user shell.

Review this skill carefully before installing. Use plain tmux mode when possible, keep browser modes on localhost, avoid sudo/root shells unless the task truly requires them, do not use it on shared or untrusted machines, and do not expose it on a LAN without firewall restriction and preferably TLS. The implementation should be hardened before routine use with sensitive sessions.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (6)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/start-url-token-web-terminal.sh:18
Finding

Arbitrary Code Execution Through a Predictable Sourced State File

Content
View full analysis
/dev/null 2>&1 || true else if [[ -n "${PROXY_PID:-}" ]] && kill -0 "${PROXY_PID}" 2>/dev/null; then kill "${PROXY_PID}" 2>/dev/null || true fi if [[ -n "${TTYD_PID:-}" ]] && kill -0 "${TTYD_PID}" 2>/dev/null; then kill "${TTYD_PID}" 2>/dev/null || true fi if [[ -n "${RUNTIME_DIR:-}" ]] && [[ -d "${RUNTIME_DIR}" ]]; then rm -rf "${RUNTIME_DIR}" || true fi fi rm -f "$state_file" } ``` Additional code paths also source the same state file: ```bash # shellcheck disable=SC1090 source "$STATE_FILE" ``` ### Technical Analysis The state-file path is derived predictably from the session name and placed directly under the shared `/tmp` directory. The script checks only whether the path exists; it does not verify that the file: - Was created by the current launcher process. - Is owned by the current user. - Has restrictive permissions. - Is a regular file rather than a symbolic link. - Contains only expected declarative fields. The Bash `source` command evaluates the entire file as shell code. Consequently, any local user who can create or replace the predictable state file can inject arbitrary commands that execute with the privileges of the user running the launcher. The subsequent execution of `bash -lc "$CLEANUP_CMD"` co ...[truncated 1082 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/start-url-token-web-terminal.sh:326
Finding

Terminal Access Token Exposed Through Insecure Predictable State Storage

Content
View full analysis
> "$METADATA_FILE" write_state_value URL "$URL" >> "$METADATA_FILE" write_state_value CLEANUP_CMD "$CLEANUP_CMD" >> "$METADATA_FILE" cp "$METADATA_FILE" "$STATE_FILE" ``` The persisted `URL` contains the bearer token: ```bash URL="http://$HOST:$PROXY_PORT/?token=$ACCESS_TOKEN" ``` ### Technical Analysis The script stores the complete terminal URL, including the access token, in a metadata file and then copies it to the predictable path `/tmp/ssh-handoff-${SESSION_NAME_SAFE}.env`. The script does not explicitly apply mode `0600` to the destination. Its effective permissions therefore depend on the invoking user's umask. Under a permissive or unusual umask, other local users may be able to read the bearer token. Because the destination is predictable and copied without explicit symbolic-link defenses, it is also exposed to race and symlink manipulation. Possession of the token is sufficient to initiate the browser-terminal session before another client establishes it or before the TTL expires. ### Attack Path 1. The attacker predicts the state-file name from the default or known tmux session name. 2. The victim launches the Mode C browser terminal. 3. The script copies the metadata, including `URL=http://.../?token=...`, into the predictable state file. 4. The attacker monitors or reads the file when permissions allow. 5. The attacker opens the URL before expiration or before the intended human consumes it. 6. The attacker receives access to the writable tmux-backed terminal. A related symlink race may redirect the copy operation ...[truncated 455 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/start-local-web-terminal.sh:40
Finding

Local Browser Terminal Advertises an Expiry That Is Not Enforced

Content
View full analysis
/tmp/ttyd-"$SESSION_NAME".log 2>&1 & PID=$! ``` The calculated timestamp is only printed: ```bash EXPIRES_AT=$EXPIRES_AT ``` ### Technical Analysis The launcher calculates and reports an expiry time but does not schedule a timer to terminate `ttyd`. No cleanup watcher or in-process TTL enforcement exists in Mode B. The `-o` option may cause `ttyd` to exit after a completed client session, but it does not enforce the advertised absolute expiry before the first connection. If no client connects, or if behavior differs across installed `ttyd` versions, the writable endpoint can remain available past the reported expiration. This contradicts the documented short-lived-access security model and may cause operators to believe access has been revoked when it remains active. ### Attack Path 1. The operator starts the local browser terminal and receives an `EXPIRES_AT` value. 2. The intended handoff does not occur, or the operator assumes the endpoint has expired. 3. Because no timer terminates `ttyd`, the process continues listening. 4. An attacker who later obtains the temporary credentials can connect to the still-active endpoint. 5. The attacker accesses the tmux-backed shell. ### Impact Assessment The defect extends the exposure window of a writable terminal beyond the operator's expectations. Exploitation grants the effective privileges of the tmux shell user and may expose authenticated SSH ...[truncated 163 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/start-local-web-terminal.sh:50
Finding

Predictable Shared Temporary Log Allows Symlink-Based File Overwrite

Content
View full analysis
/tmp/ttyd-"$SESSION_NAME".log 2>&1 & PID=$! ``` ### Technical Analysis The launcher redirects output to a predictable path in the globally writable `/tmp` directory. Shell redirection opens the destination with truncation and follows symbolic links. There is no ownership check, exclusive creation, or symbolic-link protection. The session name is also inserted directly into the pathname. Although it is quoted, quoting prevents shell word splitting rather than pathname traversal; slash components in an attacker-controlled session name can still influence the resulting path. A local attacker can create the expected path as a symbolic link to a file writable by the launcher user. When the launcher starts, the shell truncates and writes to the symlink target. ### Attack Path 1. The attacker predicts the session name or influences the session name supplied to the launcher. 2. The attacker creates `/tmp/ttyd-.log` as a symbolic link to a target file. 3. The victim invokes the launcher. 4. Shell redirection follows the symbolic link and truncates the target. 5. Subsequent `ttyd` output is written into the target file. ### Impact Assessment The attacker may corrupt or truncate any file writable by the launcher user. If the launcher runs with elevated privileges, sensitive system or application files may be damaged. Depending on the selected target and emitted log content, the issue could cause denial of service or contribute to configuration manipulation. ]]>
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/start-url-token-web-terminal.sh:324
Finding

Plaintext LAN Transport Exposes Terminal Tokens, Cookies, and Interactive Credentials

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/url-token-proxy.js:190
Finding

Global Bootstrap Window Permits Tokenless Session Acquisition

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (31)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 73)May include surrounding context.

md
./scripts/start-url-token-web-terminal.sh handoff-session

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 108)May include surrounding context.

md
./scripts/start-url-token-web-terminal.sh handoff-session

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 122)May include surrounding context.

md
./scripts/start-url-token-web-terminal.sh handoff-session

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 154)May include surrounding context.

md
./scripts/start-url-token-web-terminal.sh handoff-session

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 234)May include surrounding context.

md
./scripts/start-url-token-web-terminal.sh handoff-session

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · SKILL.md (reported line 90)May include surrounding context.

Install on Debian / Ubuntu:

bash
sudo apt update && sudo apt install -y tmux ttyd

node must also exist for Mode C because the proxy launcher uses the bundled Node script.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 236)May include surrounding context.

md
- `scripts/url-token-proxy.js`

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/design-notes.md (reported line 40)May include surrounding context.

text
ensure tmux session
create short-lived access token
start terminal backend bound to localhost
optionally start LAN-facing proxy with access checks
return connection details

Credential Access

High
Category
Privilege Escalation
Confidence
92% confidence
Finding

The script stores sensitive runtime state in a predictable path under /tmp and later sources that file as shell code. Even though values are written with shell escaping, placing a reusable token/URL and cleanup command in a world-accessible temporary namespace creates risk of disclosure, tampering, symlink attacks, or code execution if file ownership/permissions are not strictly enforced before sourcing.

Content

Scanner excerpt · scripts/start-url-token-web-terminal.sh (reported line 19)May include surrounding context.

sh
REPLACE_EXISTING="${REPLACE_EXISTING:-0}"
AUTH_GUARD_REGEX="${AUTH_GUARD_REGEX:-(^|[^[:alnum:]_])(Last login:|[@][A-Za-z0-9._-]+:|Welcome to|Linux [A-Za-z0-9._-]+|[#$] $)}"
SESSION_NAME_SAFE="$(printf '%s' "$SESSION_NAME" | tr -c '[:alnum:]._:-' '_')"
STATE_FILE="/tmp/ssh-handoff-${SESSION_NAME_SAFE}.env"
HOST="$REQUESTED_HOST"
PORT="$REQUESTED_PORT"
CLIENT_IP="$REQUESTED_CLIENT_IP"

Session Persistence

Medium
Category
Rogue Agent
Confidence
70% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 52)May include surrounding context.

md
- create temporary files under `/tmp`
- create a temporary state file
- start background processes (`ttyd`, Node proxy, cleanup watcher)
- bind local or LAN ports for temporary browser-terminal access

These behaviors are expected and are part of the documented handoff workflow.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill clearly instructs use of shell, environment variables, network-facing services, and bundled scripts, yet it declares no explicit tool scope or allowed-tools/permissions boundary. In an agent setting, that omission can cause the skill to be invoked with broader capabilities than intended, increasing the chance of unauthorized command execution, network exposure, or unsafe script launch without clear policy constraints.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: ssh-handoff
description: Create and reuse a secure shared terminal handoff when a human must authenticate first and the agent must resume work in the same shell session afterward. Use for SSH handoff, sudo handoff, browser-opened temporary terminal access, or LAN-restricted terminal sharing backed by tmux when direct agent authentication is blocked or undesirable.
---

# SSH Handoff

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/examples.md (reported line 15)May include surrounding context.

md
---
name: ssh-handoff
description: Create and reuse a secure shared terminal handoff when a human must authenticate first and the agent must resume work in the same shell session afterward. Use for SSH handoff, sudo handoff, browser-opened temporary terminal access, or LAN-restricted terminal sharing backed by tmux when direct agent authentication is blocked or undesirable.
---

# SSH Handoff

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/examples.md (reported line 17)May include surrounding context.

md
---
name: ssh-handoff
description: Create and reuse a secure shared terminal handoff when a human must authenticate first and the agent must resume work in the same shell session afterward. Use for SSH handoff, sudo handoff, browser-opened temporary terminal access, or LAN-restricted terminal sharing backed by tmux when direct agent authentication is blocked or undesirable.
---

# SSH Handoff

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/start-local-web-terminal.sh (reported line 63)May include surrounding context.

sh
---
name: ssh-handoff
description: Create and reuse a secure shared terminal handoff when a human must authenticate first and the agent must resume work in the same shell session afterward. Use for SSH handoff, sudo handoff, browser-opened temporary terminal access, or LAN-restricted terminal sharing backed by tmux when direct agent authentication is blocked or undesirable.
---

# SSH Handoff

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/start-local-web-terminal.sh (reported line 64)May include surrounding context.

sh
---
name: ssh-handoff
description: Create and reuse a secure shared terminal handoff when a human must authenticate first and the agent must resume work in the same shell session afterward. Use for SSH handoff, sudo handoff, browser-opened temporary terminal access, or LAN-restricted terminal sharing backed by tmux when direct agent authentication is blocked or undesirable.
---

# SSH Handoff

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/start-url-token-web-terminal.sh (reported line 340)May include surrounding context.

sh
---
name: ssh-handoff
description: Create and reuse a secure shared terminal handoff when a human must authenticate first and the agent must resume work in the same shell session afterward. Use for SSH handoff, sudo handoff, browser-opened temporary terminal access, or LAN-restricted terminal sharing backed by tmux when direct agent authentication is blocked or undesirable.
---

# SSH Handoff

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/start-url-token-web-terminal.sh (reported line 341)May include surrounding context.

sh
---
name: ssh-handoff
description: Create and reuse a secure shared terminal handoff when a human must authenticate first and the agent must resume work in the same shell session afterward. Use for SSH handoff, sudo handoff, browser-opened temporary terminal access, or LAN-restricted terminal sharing backed by tmux when direct agent authentication is blocked or undesirable.
---

# SSH Handoff

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The examples normalize privileged shell continuation and a browser-based terminal handoff without clearly warning that the agent may inherit an already-authenticated SSH or sudo context and gain access to sensitive terminal output. In this skill context, that omission is meaningful because the whole purpose is session sharing and post-authentication reuse, which increases the chance of unintended privilege transfer, credential exposure in terminal history/output, and unsafe use on untrusted networks or hosts.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
90% confidence
Finding

The specific recommendation to use sudo -s is more dangerous than a one-off sudo command because it creates an interactive root shell that the agent can inherit and reuse for arbitrary follow-on commands. Within this skill's design, that substantially increases blast radius if the agent misbehaves, the session state is misunderstood, or the shared terminal is accessed by an unintended party.

Content

Scanner excerpt · references/examples.md (reported line 23)May include surrounding context.

md
1. create session `admin-session`
2. let the human attach
3. let the human run `sudo -s` or a single `sudo` command
4. capture the pane and verify the shell state
5. continue carefully, capturing output after important commands

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
90% confidence
Finding

The specific recommendation to use sudo -s is more dangerous than a one-off sudo command because it creates an interactive root shell that the agent can inherit and reuse for arbitrary follow-on commands. Within this skill's design, that substantially increases blast radius if the agent misbehaves, the session state is misunderstood, or the shared terminal is accessed by an unintended party.

Content

Scanner excerpt · references/examples.md (reported line 23)May include surrounding context.

md
1. create session `admin-session`
2. let the human attach
3. let the human run `sudo -s` or a single `sudo` command
4. capture the pane and verify the shell state
5. continue carefully, capturing output after important commands

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 90)May include surrounding context.

Allow:

bash
sudo ufw allow from 192.0.2.20 to any port 48080 proto tcp

Remove later:

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/lan-restricted.md (reported line 20)May include surrounding context.

Allow:

bash
sudo ufw allow from 192.0.2.20 to any port 48080 proto tcp

Remove later:

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/lan-restricted.md (reported line 26)May include surrounding context.

Allow:

bash
sudo ufw allow from 192.0.2.20 to any port 48080 proto tcp

Remove later:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This script launches a writable web terminal bound to a configurable interface and then surfaces optional sudo ufw commands, but it provides no pre-execution confirmation gate or in-file safety interlock around the resulting network exposure. In the context of a terminal-sharing skill, that omission increases the chance of accidental exposure of an authenticated shell to a broader network than intended.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.env_credential_access

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/url-token-proxy.js:7