Back to skill

Security audit

fmr-user-guide

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent FMR operations guide, but it asks users to install by executing remote scripts directly and gives broad local mutation paths for a model-router service.

Review the install path before using this skill. Only run the FMR installer if you trust freemodel.eu.org and are comfortable executing a remote script locally; prefer downloading and inspecting/verifying installers first. Treat provider API keys and the device key as sensitive, avoid pasting real keys into shared logs or chats, and be cautious on shared machines because local admin/REST access can change router settings.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (24)

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

The command fetches an external script from the internet and executes it immediately. In the context of an installation guide, this is especially dangerous because users are primed to run it verbatim, so any upstream compromise or malicious modification results in direct code execution and host takeover under the invoking account.

Content

Scanner excerpt · references/chapters/install.md (reported line 23)May include surrounding context.

  • Linux / macOS:

    text
    curl -sSL https://freemodel.eu.org/install.sh | bash
    
  • Windows(PowerShell):

Chaining Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

The | bash pattern is a classic command-chaining anti-pattern that removes the opportunity to inspect downloaded content before execution. Because this skill is an installation guide for local software deployment, the context increases risk: it normalizes unsafe execution practices that can be exploited through supply-chain tampering or domain compromise.

Content

Scanner excerpt · references/chapters/install.md (reported line 23)May include surrounding context.

  • Linux / macOS:

    text
    curl -sSL https://freemodel.eu.org/install.sh | bash
    
  • Windows(PowerShell):

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The description says to use the skill whenever the user 'describes symptoms' such as the router not starting, switching models failing, or needing to configure a provider key. While some examples are FMR-specific, the condition is still broad because it does not clearly bound activation to explicit FMR context or provide negative examples, increasing the chance of unintended invocation from generic support language.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

md
| P4 | **版本门**(所有写操作前置;Router 关着也能执行):读 CLI 所在 zip 根 `package.json` 版本,与安装目录 `current` 指针指向版本的 `package.json` 比对 | 不一致 → **拦截一切写操作** | upgrade 章(含回退路径)。`/api/status` 可用时以 P3 的 `version` 交叉核对;端点缺失不阻塞本门(主判据是文件比对) |
| | | 一致 | 放行写操作 |

**平台拉起面**(装了未启动态;CLI 不承担 standalone 启动职责):拉起前先核对 `data/router.pid`——PID 指向的进程仍在(超时/僵死场景)→ 不拉起,转 troubleshoot 章。Linux = systemd 用户级或系统级 `free-model-router.service`;macOS = launchd `com.free-model-router.plist`;Windows = 管理员 schtasks 任务 `FreeModelRouter`/非管理员 VBS 隐藏启动项(停止需 `Stop-Process` 过滤 node+server.js)。查询时用户级与系统级**都查**——跨用户安装时,实例可能只在其安装账户下可见(Windows 任务定义硬编码安装者的 profile 路径)。

P4 落地细则:现行 standalone 便携包不含 CLI,"CLI 所在 zip 根"落地为**安装版本目录根**(zip 根即版本目录内容)。 Router 活着:比对 `GET /api/status` 的 `version` 与 `current/package.json`。 存在 Skill 形态 CLI(迁移期用户):按表比对 CLI 包根与 `current`。 无 CLI 且 Router 停止:写操作没有执行者,门自然放行。

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The document explicitly states that the local admin interface at /admin is accessible without a password on localhost and presents it as a normal management path, while only giving a warning for remote access. Even if limited to local access, this weakens security boundaries on shared, multi-user, or compromised hosts and normalizes operation of an unauthenticated admin surface without a prominent security warning.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instruction forbids a specific English phrase in user-visible text as part of a broader wording discipline, effectively constraining output language/style without offering user choice. This is a natural-language policy issue because it imposes a locale/language requirement rather than adapting to user preference.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The invocation examples are entirely in Chinese and the document consistently prescribes Chinese-language interaction, but there is no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking context. This can violate language/locale policy when a skill forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The guide instructs users to pipe remotely fetched scripts directly into bash and PowerShell without any integrity verification, pinning, or warning. This creates a supply-chain execution path where compromise of the domain, transport, hosting, or script contents leads to immediate arbitrary code execution on the user's machine.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file’s natural-language instructions are exclusively Chinese, and there is no indication that the skill is intentionally region-specific or that users can opt into another language. Under the policy, forcing a specific language without user choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The entire skill file is written in Chinese and provides no indication that users may choose another language or locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

该 markdown 文件适用 SQP-1。L05 将“升级、版本、回退、卸载、更新没生效/更新失败”作为进入条件,其中“版本”等词过于通用,缺少更具体的触发范围、上下文限制或反例,容易在一般咨询版本信息时误进入升级/卸载流程。

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Line L37 states that _meta.json claims "卸载后 OpenClaw 配置自动回滚" but the actual behavior is only deleting the provider entry rather than restoring the original file. This is a direct contradiction between packaged documentation/metadata and real behavior, fitting intent-code divergence.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The entire skill guidance is written in Chinese and includes prescriptive operational instructions, but nowhere indicates that language selection is optional or that the skill is intentionally limited to a Chinese-speaking context. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/chapters/usage.md (reported line 25)May include surrounding context.

text
BASE=http://127.0.0.1:5678
curl -s $BASE/api/providers                                     # 渠道全景
curl -s "$BASE/api/models?provider=<id>"                        # 某渠道模型清单
curl -s -X POST $BASE/api/switch-primary  -H "Content-Type: application/json" \
     -d '{"provider":"<id>","modelId":"<模型ID>"}'               # 切主模型

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The instruction '只做解释层' and the requirement to provide '中文名' indicate the skill is designed to present content in Chinese, but the file does not offer any user opt-in or alternative language choice. Under the policy, forcing a specific language without user choice is a natural-language policy violation unless the locale constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file describes the providerApiKey command, which sends and stores an API key, but it does not include a clear caution about credential sensitivity, storage implications, or safe handling. The surrounding table lists side effects, but that is not the same as a user-facing warning about privacy/security impact.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The document explicitly points users to files containing plaintext provider API keys, request journals, device identifiers, and fingerprints, but it does not warn that these artifacts are sensitive and should not be broadly shared. In a troubleshooting-oriented skill, users are especially likely to copy logs or config files into chats or tickets, which can leak credentials, usage metadata, and identifying information.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file instructs operators to kill processes, disable models/providers, restart services, roll back configuration files, and intercept all write operations, but it does not include a clear warning that these actions may disrupt service or alter system state. Under the markdown-file criteria for SQP-2, descriptions of behaviors affecting system integrity should disclose such risks to the user.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/data/provider-registration.md (reported line 10)May include surrounding context.

1. 拉权威列表

text
curl http://127.0.0.1:5678/api/providers

响应 {ok: true, data: {<渠道id>: {...}}},每渠道关注字段:id(标识)、website(注册入口 URL)、hasApiKey(是否已配 key)、enabled(启停)、status(运行状态)。CLI providers 命令仅作人读辅助——打印层没有 website 列,注册链接以本接口为准。

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documented workflow instructs sending a provider API key to a local HTTP endpoint in the JSON request body without explicitly warning that the transport is plaintext HTTP and that any process with local interception capability, logging, shell history capture, or local proxy visibility could expose the secret. While the endpoint is bound to 127.0.0.1, this reduces but does not eliminate risk on multi-user, monitored, proxied, or compromised hosts, and the skill context explicitly normalizes handling secrets through insecure-by-default examples.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file instructs the agent to create a markdown document in the repository/workspace ('写成 markdown 文件') when the user asks to archive or save a summary, but it does not require an explicit warning or confirmation immediately before modifying the filesystem. In an agent setting, implicit write behavior can lead to unintended local file creation or repository changes, especially because nearby text also discusses repository write-back flows, which normalizes mutation actions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

All user-facing instructions in this file are Chinese-only, including activation phrases and procedural guidance. Under the policy, forcing a specific language without user opt-in can be a locale/language policy violation unless clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

该文件全文以中文给出操作说明,且未见任何关于可切换语言、遵循用户语言偏好或仅适用于特定语言受众的说明。按 SQP-3,若技能在自然语言层面隐含强制特定语言而无用户选择,可能构成语言/locale 政策问题。

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

Rows for stop, uninstall, mark-notified, and mark-read state that files are deleted or directly modified, but the document does not clearly warn users that these operations change local state and may be irreversible in practice. Describing a side effect is useful, but a distinct caution is expected for operations affecting system integrity or user data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.