Back to skill

Security audit

Vpn Setup

Security checks for vulnerabilities and agentic risk

Overview

This VPN setup skill does what it claims, but its OpenVPN path runs an unverified third-party installer as root and its high-impact system changes are under-disclosed.

Review this skill before installing. Use the WireGuard path only on a dedicated server after backups and after confirming the firewall, routing, service, and key-file changes are acceptable. Avoid the OpenVPN path unless the remote installer is pinned and verified or replaced with reviewed local code.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
scripts/vpn-install.sh:163
Finding

Unverified Remote Installer Executed with Root Privileges

Content
View full analysis

Vulnerability Details

File Location: scripts/vpn-install.sh, lines 163–180
Vulnerability Type: Unpinned remote payload retrieval and privileged execution
Risk Level: Critical

Vulnerable Code

bash
# Install using official script
curl -O https://raw.githubusercontent.com/angristan/openvpn-install/master/openvpn-install.sh
chmod +x openvpn-install.sh

# Set environment variables for automated install
export APPROVE_INSTALL=y
export APPROVE_IP=y
export IP=${SERVER_IP}
export ENDPOINT=${SERVER_IP}
export PORT=${SERVER_PORT_OV}
export PROTOCOL=udp
export DNS=${DNS_SERVER}
export COMPRESSION_ENABLED=n
export CLIENT=${CLIENT_NAME}
export PASS=1

# Run installer
./openvpn-install.sh

The script separately enforces root execution at lines 51–57:

bash
check_root() {
    if [ "$EUID" -ne 0 ]; then
        echo -e "${RED}请使用 sudo 运行此脚本${NC}"
        exit 1
    fi
}

Technical Analysis

The OpenVPN installation path downloads a shell script from the mutable master branch of a third-party personal GitHub repository and immediately executes it. The downloaded artifact is not pinned to an immutable commit or release, and its checksum or cryptographic signature is not verified.

Although HTTPS protects the connection in transit, it does not guarantee that the repository content remains identical to the version reviewed with this Skill. A repository compromise, maintainer account takeover, malicious upstream change, or compromised release process could alter the effective code executed by the Skill without requiring any modification to the Skill package.

The downloaded script inherits unrestricted root privileges because main() calls check_root before invoking either installation path. It is also configured for noninteractive execution through exported approval variables, reducing the opportunity for the operator to notice unexpected upstream actions.

Attack Path

  1. An attacker compromises the upstream repository, its maintai ...[truncated 1350 chars]
Remediation
View remediation

Remediation Suggestions

  1. Vendor a reviewed OpenVPN installation implementation inside the Skill package so that the audited code is the code executed.
  2. If remote retrieval is unavoidable, pin the URL to an immutable commit hash or versioned release rather than master.
  3. Publish and hard-code an expected SHA-256 or stronger digest. Verify it before granting execute permission, and terminate immediately if verification fails.
  4. Prefer a cryptographically signed release and verify the signature against a trusted, pinned maintainer key.
  5. Download with failure-aware and restrictive options, such as curl --fail --show-error --location, into a securely created temporary directory.
  6. Review the pinned installer and minimize its privileges. Separate package installation and system configuration into narrowly scoped privileged operations where practical.
  7. Present the immutable version, source, and verified digest to the operator before execution.
  8. Document that the OpenVPN path retrieves and executes third-party code as root, including the associated supply-chain risk.
  9. Add automated tests or policy checks that reject mutable branch URLs and remote scripts lacking integrity verification.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (28)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This path fetches and runs a third-party installer as root, with no integrity verification and no explicit warning to the operator. Because the script already enforces root execution, any compromise of the downloaded content results in immediate privileged code execution on the host.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README promotes one-command VPN installation and automation, but it does not clearly warn users that the process will change firewall/routing settings, enable services, and generate sensitive client credentials. In a VPN setup skill, those side effects are expected, but failing to disclose them increases the risk of unsafe execution and accidental exposure of private configuration files.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill clearly instructs execution of shell-based installation commands, but it does not declare any explicit tool scope such as allowed-tools or permissions. That creates a mismatch between documented behavior and security controls, increasing the chance the skill can invoke shell actions without transparent review or least-privilege constraints.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The trigger phrase "安装 VPN" is broad enough to match generic requests about VPN software, which could cause this skill to activate unexpectedly and steer users into running privileged installation steps. Because the skill sets up server-side VPN software, unintended invocation raises risk beyond a harmless informational response.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Standalone activators like "wireguard" and "openvpn" are highly ambiguous and may match informational, troubleshooting, or client-side questions unrelated to server deployment. In this skill, accidental activation is more dangerous because the documented workflow leads to shell execution and privileged system changes.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 95)May include surrounding context.

bash
# 查看状态
sudo systemctl status wg-quick@wg0

# 添加客户端
wg genkey | tee /etc/wireguard/client.key | wg pubkey > /etc/wireguard/client.pub

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 104)May include surrounding context.

bash
# 查看状态
sudo systemctl status wg-quick@wg0

# 添加客户端
wg genkey | tee /etc/wireguard/client.key | wg pubkey > /etc/wireguard/client.pub

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 111)May include surrounding context.

bash
# 查看状态
sudo systemctl status wg-quick@wg0

# 添加客户端
wg genkey | tee /etc/wireguard/client.key | wg pubkey > /etc/wireguard/client.pub

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 117)May include surrounding context.

bash
# 查看状态
sudo systemctl status wg-quick@wg0

# 添加客户端
wg genkey | tee /etc/wireguard/client.key | wg pubkey > /etc/wireguard/client.pub

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 134)May include surrounding context.

bash
# 查看状态
sudo systemctl status wg-quick@wg0

# 添加客户端
wg genkey | tee /etc/wireguard/client.key | wg pubkey > /etc/wireguard/client.pub

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

bash
# 查看状态
sudo systemctl status wg-quick@wg0

# 添加客户端
wg genkey | tee /etc/wireguard/client.key | wg pubkey > /etc/wireguard/client.pub

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 65)May include surrounding context.

bash
# 查看状态
sudo systemctl status wg-quick@wg0

# 添加客户端
wg genkey | tee /etc/wireguard/client.key | wg pubkey > /etc/wireguard/client.pub

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 72)May include surrounding context.

bash
# 查看状态
sudo systemctl status wg-quick@wg0

# 添加客户端
wg genkey | tee /etc/wireguard/client.key | wg pubkey > /etc/wireguard/client.pub

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 98)May include surrounding context.

bash
# 查看状态
sudo systemctl status wg-quick@wg0

# 添加客户端
wg genkey | tee /etc/wireguard/client.key | wg pubkey > /etc/wireguard/client.pub

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 99)May include surrounding context.

bash
# 查看状态
sudo systemctl status wg-quick@wg0

# 添加客户端
wg genkey | tee /etc/wireguard/client.key | wg pubkey > /etc/wireguard/client.pub

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 98)May include surrounding context.

md
# Check root
check_root() {
    if [ "$EUID" -ne 0 ]; then
        echo -e "${RED}请使用 sudo 运行此脚本${NC}"
        exit 1
    fi
}

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 101)May include surrounding context.

md
# Check root
check_root() {
    if [ "$EUID" -ne 0 ]; then
        echo -e "${RED}请使用 sudo 运行此脚本${NC}"
        exit 1
    fi
}

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 114)May include surrounding context.

md
# Check root
check_root() {
    if [ "$EUID" -ne 0 ]; then
        echo -e "${RED}请使用 sudo 运行此脚本${NC}"
        exit 1
    fi
}

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 137)May include surrounding context.

md
# Check root
check_root() {
    if [ "$EUID" -ne 0 ]; then
        echo -e "${RED}请使用 sudo 运行此脚本${NC}"
        exit 1
    fi
}

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/vpn-install.sh (reported line 59)May include surrounding context.

sh
# Check root
check_root() {
    if [ "$EUID" -ne 0 ]; then
        echo -e "${RED}请使用 sudo 运行此脚本${NC}"
        exit 1
    fi
}

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The WireGuard installation path writes /etc/wireguard/wg0.conf, enables IP forwarding via /etc/sysctl.d/99-wireguard.conf, changes iptables behavior, and enables a systemd service. These are persistent system-level changes, but the script does not clearly warn the user beforehand about firewall, routing, and boot-time configuration modifications.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/vpn-install.sh (reported line 114)May include surrounding context.

sh
sysctl -p /etc/sysctl.d/99-wireguard.conf
    
    # Enable service
    systemctl enable wg-quick@wg0
    systemctl start wg-quick@wg0
    
    # Generate client config

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The OpenVPN path downloads a shell script from GitHub and executes it as root without pinning a version, verifying a checksum/signature, or vendoring the code. This creates a supply-chain and remote code execution risk: if the upstream script or delivery path is compromised, arbitrary commands will run with full system privileges.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.