Back to skill

Security audit

vscode-tunnel

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to do what it says, but it starts a background remote VS Code tunnel and runs a downloaded CLI without strong safeguards, so it should be reviewed before use.

Install this only if you intentionally want a VS Code Remote Tunnel from the container and understand that it can provide remote terminal access to the environment after Microsoft authorization. Prefer using it in a low-privilege container, start it only on explicit request, stop it when finished, and consider adding CLI integrity verification and narrower activation wording before relying on it.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Warning
Location
tunnel.sh:17
Finding

Unverified Remote VS Code CLI Download and Execution

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
tunnel.sh:126
Finding

Broad Process Matching Can Terminate an Unrelated Process

Content
View full analysis
/dev/null | head -1 ``` ```bash cmd_stop() { log_info "Stopping VS Code Tunnel..." local pid=$(get_tunnel_pid) if [ -z "$pid" ]; then log_warn "No running tunnel found" exit 0 fi if kill "$pid" 2>/dev/null; then rm -f "$PID_FILE" log_success "Tunnel stopped (PID: $pid)" else log_error "Failed to stop, may lack permissions" exit 1 fi } ``` ### Technical Analysis If the PID file is missing, stale, or does not identify a live process, `get_tunnel_pid` searches all visible command lines for the substring `code tunnel` and selects the first match. The script does not verify that the selected process: - Was started by this script. - Uses the expected `$CLI_DIR/code` executable. - Belongs to the expected user. - Uses the expected CLI directory or log file. - Has a start time corresponding to the stored process instance. - Is actually the managed VS Code Tunnel rather than an unrelated command with matching arguments. `cmd_stop` then sends the default termination signal to that PID. Full-command-line substring matching is insufficient as a security or ownership boundary and can produce false positives. A deliberately crafted same-user process can also satisfy the search pattern. ### Attack Path 1. The tunnel PID file is absent, stale, corrupted, or references a process that is no longer running. 2. Another process visible to the invoking user has `code tunnel` somewhere in its command line. 3. The user invokes `tunnel.sh stop`. 4. The fallback `pgrep -f` search selects the first matching process without validating its executable or ownership relationship to this Skill. 5. `cmd_stop` sends a termination signal to ...[truncated 638 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill invokes shell commands that start a remote access tunnel, but it declares no explicit tool scope or permission boundaries. This is dangerous because an agent may execute privileged shell actions without clear user consent constraints, and the tunnel exposes remote terminal access that can materially expand access to the container.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad enough that routine requests like 'connect vscode' or 'vscode remote' could activate a skill that launches remote connectivity. In this context, accidental activation is more dangerous than usual because the action creates a background remote tunnel and may expose terminal access beyond the local session.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · tunnel.sh (reported line 54)May include surrounding context.

sh
check_dependencies() {
    local missing=()
    
    for cmd in curl tar grep; do
        if ! command -v "$cmd" &> /dev/null; then
            missing+=("$cmd")
        fi

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

Running code tunnel under nohup in the background creates persistent remote access from the container to the VS Code tunnel service. In this skill context, that is the core functionality, but it is still security-sensitive because it establishes long-lived remote terminal access and can survive the invoking shell session, increasing exposure if started unintentionally or by an untrusted user.

Content

Scanner excerpt · tunnel.sh (reported line 163)May include surrounding context.

sh
log_info "Launching tunnel..."
    cd "$CLI_DIR"
    
    nohup ./code tunnel \
        --accept-server-license-terms \
        --name "$tunnel_name" \
        > "$LOG_FILE" 2>&1 &

Static analysis

No suspicious patterns detected.