Back to skill

Security audit

Mihomo Proxy Manager

Security checks for vulnerabilities and agentic risk

Overview

This proxy-management skill is mostly purpose-aligned, but it includes unsafe configuration-generation code and persistent service setup that require careful review before installation.

Install only if you understand and accept that this skill can alter a system proxy service. Before use, review and harden the systemd unit, run generation as an unprivileged user, replace shell-based curl invocation with safe argument handling, avoid fixed /tmp files, back up config.yaml, validate a staged candidate config, and confirm before restarting or enabling the service.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/gen_config.js:102
Finding

Shell Command Injection Through the Subscription URL

Content
View full analysis
/tmp/injection-proof; # ``` 3. The resulting shell command is effectively interpreted as: ```sh curl -sL ''; id > /tmp/injection-proof; #' -o /tmp/sub_raw.txt ``` 4. The shell executes the injected command. 5. If the generator was launched with elevated privileges, the injected command executes with those same privileges. ### Impact Assessment Successful exploitation provides arbitrary command execution with the privileges of the Node.js process. When run as root, an attacker could read or alter protected files, install additional services, replace binaries, steal proxy credentials, establish persistence, or fully compromise the host. ]]>
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/gen_config.js:102
Finding

Predictable Shared Temporary File Enables Symlink Attacks

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/gen_config.js:65
Finding

Subscription-Controlled Values Are Embedded in YAML Without Safe Serialization

Content
View full analysis
Remediation
View remediation

T06 · System Persistence

Error
Location
SKILL.md:121
Finding

Boot-Time System Service Persistence Is Not Explicitly Limited or Hardened

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill clearly instructs shell-capable operations such as curl, systemctl, and local binary execution, but it does not declare any explicit tool scope or permissions boundary. This increases the chance that an agent can perform powerful host-level actions without transparent authorization controls, especially on a server managing network proxy behavior.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

The skill instructs making an outbound request to httpbin.org through the local proxy, which transmits host/network metadata such as the egress IP to an external third party. In a proxy-management skill this behavior is contextually relevant for testing, but it still creates data egress to an external service and may violate restrictive environments or leak operational details.

Content

Scanner excerpt · SKILL.md (reported line 22)May include surrounding context.

测试代理连通性

bash
curl -s --max-time 10 -x http://127.0.0.1:7890 https://httpbin.org/ip

验证配置

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The subscription update workflow downloads remote content, generates configuration, validates it, and restarts the proxy service without any explicit warning about overwriting active configuration or interrupting connectivity. In this context, a bad subscription or mistaken change can immediately break network routing, replace trusted endpoints, or cause service outage on the host.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 115)May include surrounding context.

md
## 注意事项

- mihomo 运行在 systemd 下,不要用 nohup 手动启动
- 修改配置后先验证(`-t`)再重启
- trojan ws 节点如果 Host 为空会导致配置验证失败
- 订阅内容可能是无换行的 base64,需先解码处理

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 125)May include surrounding context.

md
1. 下载 mihomo 二进制放到 `/opt/mihomo`
2. 创建配置目录 `/opt/mihomo-config/` 并放入 `config.yaml`
3. 创建 systemd service 文件(参考 mihomo 官方文档)
4. `systemctl enable --now mihomo`
5. 验证:`curl -x http://127.0.0.1:7890 https://httpbin.org/ip`

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The natural-language comments and generated grouping behavior are hard-coded around Chinese/Japanese locale labels such as 日本, 美国, 香港, and related region-specific defaults. There is no indication that users can opt into another language or locale, which conflicts with the policy against forcing a specific language without user choice.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script overwrites /opt/mihomo-config/config.yaml via fs.writeFileSync, which modifies a system configuration file. Although it logs the destination after writing, there is no prior warning or confirmation before the file write occurs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

All user-facing instructions and the skill description are written in Chinese, with no indication that another language can be used or that the locale restriction is intentional and justified. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/gen_config.js:91