T03 · Remote Payload Retrieval and Execution
- Location
tunnel.sh:17- Finding
Unverified Remote VS Code CLI Download and Execution
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill appears to do what it says, but it starts a background remote VS Code tunnel and runs a downloaded CLI without strong safeguards, so it should be reviewed before use.
Install this only if you intentionally want a VS Code Remote Tunnel from the container and understand that it can provide remote terminal access to the environment after Microsoft authorization. Prefer using it in a low-privilege container, start it only on explicit request, stop it when finished, and consider adding CLI integrity verification and narrower activation wording before relying on it.
tunnel.sh:17Unverified Remote VS Code CLI Download and Execution
tunnel.sh:126Broad Process Matching Can Terminate an Unrelated Process
The skill invokes shell commands that start a remote access tunnel, but it declares no explicit tool scope or permission boundaries. This is dangerous because an agent may execute privileged shell actions without clear user consent constraints, and the tunnel exposes remote terminal access that can materially expand access to the container.
The trigger phrases are broad enough that routine requests like 'connect vscode' or 'vscode remote' could activate a skill that launches remote connectivity. In this context, accidental activation is more dangerous than usual because the action creates a background remote tunnel and may expose terminal access beyond the local session.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
check_dependencies() {
local missing=()
for cmd in curl tar grep; do
if ! command -v "$cmd" &> /dev/null; then
missing+=("$cmd")
fi
Running code tunnel under nohup in the background creates persistent remote access from the container to the VS Code tunnel service. In this skill context, that is the core functionality, but it is still security-sensitive because it establishes long-lived remote terminal access and can survive the invoking shell session, increasing exposure if started unintentionally or by an untrusted user.
log_info "Launching tunnel..."
cd "$CLI_DIR"
nohup ./code tunnel \
--accept-server-license-terms \
--name "$tunnel_name" \
> "$LOG_FILE" 2>&1 &
No suspicious patterns detected.