Back to skill

Security audit

AstraFlow 远程桌面沙箱与云主机连接

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does what it says, but it controls billable cloud sandboxes and has unsafe URL handling that deserves review before installation.

Install only if you intend to let the skill use your AstraFlow API key to create, expose, and destroy billable cloud desktop sandboxes. Avoid passing untrusted or attacker-controlled URLs to --url until the shell quoting issue is fixed, be careful with kill --all --force, and remember the generated VNC password is printed and embedded in the access URL.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (32)

Cloud Metadata Access

High
Category
Server-Side Request Forgery
Confidence
90% confidence
Finding

Code accesses a cloud instance metadata endpoint (e.g. 169.254.169.254). A single request can return temporary IAM credentials, making this a high-value SSRF target for credential theft.

Content

Scanner excerpt · scripts/sandbox_ctl.py (reported line 161)May include surrounding context.

python
if parsed.scheme.lower() not in ("http", "https"):
        raise ValueError(f"无效的 URL 协议 '{parsed.scheme}',仅允许 'http://' 与 'https://'。")
    hostname = (parsed.hostname or "").lower()
    unsafe_hosts = ("localhost", "127.0.0.1", "0.0.0.0", "169.254.169.254")
    if hostname in unsafe_hosts or hostname.startswith("192.168.") or hostname.startswith("10."):
        raise ValueError(f"禁止指向回环、私网子网或云元数据端点({hostname})。")
    return raw_url.strip()

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · scripts/sandbox_ctl.py (reported line 216)May include surrounding context.

python
tz = "America/Los_Angeles" if region == "us-ca" else "Asia/Shanghai"
        print(f"正在对齐系统时区至 {tz}...")
        sb.commands.run(
            f"sudo ln -sf /usr/share/zoneinfo/{tz} /etc/localtime; echo '{tz}' | sudo tee /etc/timezone >/dev/null",
            timeout=30,
        )

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill declares operational capabilities involving environment variables, network access, and shell execution, but does not define any explicit tool scope or permissions boundary. This increases the risk that an agent may invoke broader-than-necessary actions, including handling secrets like API keys or executing destructive lifecycle commands, without clear least-privilege constraints.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file’s natural-language content is consistently Chinese, including the description, operating instructions, and warnings. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly justified, which is not stated here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Line L16 describes automatic timezone alignment to a specific locale, and L26 further reinforces that the system changes /etc/localtime to America/Los_Angeles. This is a natural-language locale policy concern because the file presents a forced locale behavior rather than offering a user-selectable option or clearly documenting opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This Python skill uses Chinese-only natural-language strings in the module docstring and all user-facing print messages. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is clearly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code file contains natural-language strings and help text entirely in Chinese, including the module docstring and subsequent CLI output/help messages. The policy requires flagging language or locale constraints when the skill forces a specific language without user opt-in, and this file provides no mechanism to select another language or indication that it is intentionally region-specific.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The module docstring states that destroy operations occur only under '严格安全确认', implying a strong confirmation safeguard. However, the implementation allows kill --all -f to skip the interactive confirmation entirely and destroy all matching sandboxes across regions, which is a broader and less strictly confirmed behavior than the documentation suggests.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/sandbox_ctl.py (reported line 64)May include surrounding context.

python
done
WATCHER
chmod +x "$WATCH"
setsid nohup "$WATCH" >/dev/null 2>&1 </dev/null &

echo "[2/7] 检查 noVNC 与 websockify..."
if ! command -v websockify >/dev/null 2>&1 || [ ! -f /usr/share/novnc/vnc.html ]; then

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/sandbox_ctl.py (reported line 74)May include surrounding context.

python
done
WATCHER
chmod +x "$WATCH"
setsid nohup "$WATCH" >/dev/null 2>&1 </dev/null &

echo "[2/7] 检查 noVNC 与 websockify..."
if ! command -v websockify >/dev/null 2>&1 || [ ! -f /usr/share/novnc/vnc.html ]; then

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/sandbox_ctl.py (reported line 80)May include surrounding context.

python
done
WATCHER
chmod +x "$WATCH"
setsid nohup "$WATCH" >/dev/null 2>&1 </dev/null &

echo "[2/7] 检查 noVNC 与 websockify..."
if ! command -v websockify >/dev/null 2>&1 || [ ! -f /usr/share/novnc/vnc.html ]; then

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/sandbox_ctl.py (reported line 85)May include surrounding context.

python
done
WATCHER
chmod +x "$WATCH"
setsid nohup "$WATCH" >/dev/null 2>&1 </dev/null &

echo "[2/7] 检查 noVNC 与 websockify..."
if ! command -v websockify >/dev/null 2>&1 || [ ! -f /usr/share/novnc/vnc.html ]; then

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/sandbox_ctl.py (reported line 90)May include surrounding context.

python
done
WATCHER
chmod +x "$WATCH"
setsid nohup "$WATCH" >/dev/null 2>&1 </dev/null &

echo "[2/7] 检查 noVNC 与 websockify..."
if ! command -v websockify >/dev/null 2>&1 || [ ! -f /usr/share/novnc/vnc.html ]; then

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/sandbox_ctl.py (reported line 101)May include surrounding context.

python
done
WATCHER
chmod +x "$WATCH"
setsid nohup "$WATCH" >/dev/null 2>&1 </dev/null &

echo "[2/7] 检查 noVNC 与 websockify..."
if ! command -v websockify >/dev/null 2>&1 || [ ! -f /usr/share/novnc/vnc.html ]; then

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/sandbox_ctl.py (reported line 107)May include surrounding context.

python
done
WATCHER
chmod +x "$WATCH"
setsid nohup "$WATCH" >/dev/null 2>&1 </dev/null &

echo "[2/7] 检查 noVNC 与 websockify..."
if ! command -v websockify >/dev/null 2>&1 || [ ! -f /usr/share/novnc/vnc.html ]; then

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/sandbox_ctl.py (reported line 64)May include surrounding context.

python
done
WATCHER
chmod +x "$WATCH"
setsid nohup "$WATCH" >/dev/null 2>&1 </dev/null &

echo "[2/7] 检查 noVNC 与 websockify..."
if ! command -v websockify >/dev/null 2>&1 || [ ! -f /usr/share/novnc/vnc.html ]; then

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/sandbox_ctl.py (reported line 74)May include surrounding context.

python
done
WATCHER
chmod +x "$WATCH"
setsid nohup "$WATCH" >/dev/null 2>&1 </dev/null &

echo "[2/7] 检查 noVNC 与 websockify..."
if ! command -v websockify >/dev/null 2>&1 || [ ! -f /usr/share/novnc/vnc.html ]; then

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/sandbox_ctl.py (reported line 80)May include surrounding context.

python
done
WATCHER
chmod +x "$WATCH"
setsid nohup "$WATCH" >/dev/null 2>&1 </dev/null &

echo "[2/7] 检查 noVNC 与 websockify..."
if ! command -v websockify >/dev/null 2>&1 || [ ! -f /usr/share/novnc/vnc.html ]; then

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/sandbox_ctl.py (reported line 85)May include surrounding context.

python
done
WATCHER
chmod +x "$WATCH"
setsid nohup "$WATCH" >/dev/null 2>&1 </dev/null &

echo "[2/7] 检查 noVNC 与 websockify..."
if ! command -v websockify >/dev/null 2>&1 || [ ! -f /usr/share/novnc/vnc.html ]; then

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/sandbox_ctl.py (reported line 90)May include surrounding context.

python
done
WATCHER
chmod +x "$WATCH"
setsid nohup "$WATCH" >/dev/null 2>&1 </dev/null &

echo "[2/7] 检查 noVNC 与 websockify..."
if ! command -v websockify >/dev/null 2>&1 || [ ! -f /usr/share/novnc/vnc.html ]; then

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/sandbox_ctl.py (reported line 101)May include surrounding context.

python
done
WATCHER
chmod +x "$WATCH"
setsid nohup "$WATCH" >/dev/null 2>&1 </dev/null &

echo "[2/7] 检查 noVNC 与 websockify..."
if ! command -v websockify >/dev/null 2>&1 || [ ! -f /usr/share/novnc/vnc.html ]; then

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/sandbox_ctl.py (reported line 107)May include surrounding context.

python
done
WATCHER
chmod +x "$WATCH"
setsid nohup "$WATCH" >/dev/null 2>&1 </dev/null &

echo "[2/7] 检查 noVNC 与 websockify..."
if ! command -v websockify >/dev/null 2>&1 || [ ! -f /usr/share/novnc/vnc.html ]; then

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/sandbox_ctl.py (reported line 126)May include surrounding context.

python
done
WATCHER
chmod +x "$WATCH"
setsid nohup "$WATCH" >/dev/null 2>&1 </dev/null &

echo "[2/7] 检查 noVNC 与 websockify..."
if ! command -v websockify >/dev/null 2>&1 || [ ! -f /usr/share/novnc/vnc.html ]; then

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/sandbox_ctl.py (reported line 68)May include surrounding context.

python
echo "[2/7] 检查 noVNC 与 websockify..."
if ! command -v websockify >/dev/null 2>&1 || [ ! -f /usr/share/novnc/vnc.html ]; then
  DEBIAN_FRONTEND=noninteractive sudo apt-get update -qq
  DEBIAN_FRONTEND=noninteractive sudo apt-get install -y -qq novnc websockify
fi

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/sandbox_ctl.py (reported line 69)May include surrounding context.

python
echo "[2/7] 检查 noVNC 与 websockify..."
if ! command -v websockify >/dev/null 2>&1 || [ ! -f /usr/share/novnc/vnc.html ]; then
  DEBIAN_FRONTEND=noninteractive sudo apt-get update -qq
  DEBIAN_FRONTEND=noninteractive sudo apt-get install -y -qq novnc websockify
fi

Static analysis

No suspicious patterns detected.