T03 · Remote Payload Retrieval and Execution
- Location
DEPLOYMENT.md:141- Finding
Unverified Remote Executables Are Downloaded and Installed
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill fits its game-agent purpose, but its default setup can run mutable remote code and expose a local control API too broadly.
Review before installing. Prefer a pinned image digest or verified release binary, bind the agent API to 127.0.0.1, avoid the plaintext public test server for real use, and understand that the agent stores an auth token and persistent game data locally.
DEPLOYMENT.md:141Unverified Remote Executables Are Downloaded and Installed
SKILL.md:27Mutable Container Image Is Pulled and Executed by the Quick-Start Command
SKILL.md:27Quick-Start Command Publishes a Sensitive Control API on All Interfaces
DEPLOYMENT.md:21Public Game Server Is Recommended Over Plaintext WebSocket Transport
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
rm -rf ~/.cyber-jianghu/config/agent.yaml docker restart cyber-jianghu-agent
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
rm -rf ~/.cyber-jianghu/config/agent.yaml docker restart cyber-jianghu-agent
Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.
Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.
Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
install -m 755 cyber-jianghu-agent ~/.local/bin/
# 2. 创建 systemd 服务
mkdir -p ~/.config/systemd/user
cat > ~/.config/systemd/user/cyber-jianghu-agent.service << 'EOF'
[Unit]
Description=Cyber-Jianghu Agent
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
# 4. 启用并启动
systemctl --user daemon-reload
systemctl --user enable --now cyber-jianghu-agent
# 5. 启用 linger(使服务在登出后继续运行)
sudo loginctl enable-linger $USER
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
systemctl --user enable --now cyber-jianghu-agent
sudo loginctl enable-linger $USER
#### macOS (launchd)
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
install -m 755 cyber-jianghu-agent ~/.local/bin/
# 2. 创建数据目录
mkdir -p ~/.cyber-jianghu/config ~/.cyber-jianghu/data
# 3. 创建 launchd plist
cat > ~/Library/LaunchAgents/com.8kugames.cyber-jianghu-agent.plist << 'EOF'
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
# 2. 创建数据目录
mkdir -p ~/.cyber-jianghu/config ~/.cyber-jianghu/data
# 3. 创建 launchd plist
cat > ~/Library/LaunchAgents/com.8kugames.cyber-jianghu-agent.plist << 'EOF'
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
# 2. 创建数据目录
mkdir -p ~/.cyber-jianghu/config ~/.cyber-jianghu/data
# 3. 创建 launchd plist
cat > ~/Library/LaunchAgents/com.8kugames.cyber-jianghu-agent.plist << 'EOF'
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
# 2. 创建数据目录
mkdir -p ~/.cyber-jianghu/config ~/.cyber-jianghu/data
# 3. 创建 launchd plist
cat > ~/Library/LaunchAgents/com.8kugames.cyber-jianghu-agent.plist << 'EOF'
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
# 2. 创建数据目录
mkdir -p ~/.cyber-jianghu/config ~/.cyber-jianghu/data
# 3. 创建 launchd plist
cat > ~/Library/LaunchAgents/com.8kugames.cyber-jianghu-agent.plist << 'EOF'
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
# 2. 创建数据目录
mkdir -p ~/.cyber-jianghu/config ~/.cyber-jianghu/data
# 3. 创建 launchd plist
cat > ~/Library/LaunchAgents/com.8kugames.cyber-jianghu-agent.plist << 'EOF'
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
# 2. 创建数据目录
mkdir -p ~/.cyber-jianghu/config ~/.cyber-jianghu/data
# 3. 创建 launchd plist
cat > ~/Library/LaunchAgents/com.8kugames.cyber-jianghu-agent.plist << 'EOF'
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
# 3. 创建 launchd plist
cat > ~/Library/LaunchAgents/com.8kugames.cyber-jianghu-agent.plist << 'EOF'
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
<key>Label</key>
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
EOF
launchctl load ~/Library/LaunchAgents/com.8kugames.cyber-jianghu-agent.plist
---
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# 2. 如果配置丢失或令牌无效,需要重新注册
# 调用注册接口(首次运行时会自动注册)
curl -X POST http://localhost:23340/api/v1/character/register \
-H "Content-Type: application/json" \
-d '{"name": "你的角色名", ...}'
Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.
docker logs cyber-jianghu-agent
# 2. 检查持久化数据
ls -la ~/.cyber-jianghu/config/ ~/.cyber-jianghu/data/
# 3. 如果配置损坏,删除后重新注册
# ⚠️ 注意:agent.yaml 中包含 auth_token,删除后需重新注册角色
The skill text is written as a direct instruction to the agent in Chinese and frames the agent as the user's sole interface to the world, but it does not state that Chinese is optional or user-selectable. This creates a natural-language policy issue because the skill effectively imposes a specific language/locale without documented opt-in or justification.
The documentation tells users to run a container from ghcr.io/8kugames/cyber-jianghu-agent:latest, which is a mutable tag rather than a pinned version or digest. This creates a supply-chain risk: a future image update, compromised registry account, or malicious retag could cause users to deploy unexpected code with network exposure on port 23340.
No suspicious patterns detected.