Back to skill

Security audit

ZenHeart 管理运维

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a legitimate ZenHeart L0 admin guide, but its install path depends on mutable remote components while handling very powerful credentials and admin actions.

Install only for authorized ZenHeart L0 operators. Pin and verify Zenlink and zen-editorial-review before use, build them away from production tokens, keep tokens in a secret manager or environment variables only, and require tickets or explicit human approval for destructive or platform-wide actions.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:178
Finding

Unverified Mutable Remote Dependencies in a Privileged L0 Runtime

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:178-179 and SKILL.md:293-296
Vulnerability Type: Unverified third-party dependency and Skill installation
Risk Level: Medium

Vulnerable Instructions

SKILL.md:178-179:

text
npm ci && npm run build
https://zenheart.net/v2/faq/skills/zen-editorial-review
https://zenheart.net/v2/faq/skills/zen-editorial-review/bundle

SKILL.md:293-296:

text
npm ci && npm run build
node dist/cli.js
https://zenheart.net/#/faq#zenlink

Technical Analysis

The Skill directs operators to obtain, build, and use Zenlink from an external site or site-hosted archive. It also directs them to install the zen-editorial-review Skill from a remote URL. The audited artifact does not include these dependency sources, their lockfiles, cryptographic checksums, signatures, or immutable commit references.

As a result, the effective code and instruction payload used at runtime can differ from what was available when this Skill was reviewed. The npm ci operation may execute package lifecycle scripts from the externally obtained Zenlink source and its dependency tree. A remotely installed Skill can also introduce new Agent instructions that are outside this audit scope.

HTTPS protects data in transit but does not establish artifact immutability. It does not protect against compromise of the hosting account, build pipeline, package registry, dependency publisher, or upstream source archive.

This issue is particularly sensitive because the documented runtime receives ZENLINK_TOKEN and operates as a Level-0 administrator with platform-wide governance capabilities.

Attack Path

  1. An attacker compromises the hosted Zenlink archive, an upstream npm dependency, the dependency publication pipeline, or the remote editorial-review Skill bundle.
  2. The attacker replaces the expected resource with malicious code or malicious Agent instructions wh ...[truncated 1308 chars]
Remediation
View remediation

Remediation Suggestions

  1. Vendor reviewed Zenlink source code, its package manifest, and its lockfile in the audited repository or distribute it through a controlled internal artifact registry.
  2. Pin every remote component to an immutable release, commit hash, or content-addressed artifact rather than a mutable URL.
  3. Publish SHA-256 checksums and cryptographic signatures for Zenlink archives and Skill bundles. Verify both before installation or execution.
  4. Pin zen-editorial-review to a specific reviewed version and reject bundles whose digest does not match the approved value.
  5. Inspect npm dependencies before permitting lifecycle scripts. Use npm ci --ignore-scripts for initial verification, then explicitly execute only reviewed build steps.
  6. Generate and review a software bill of materials and scan transitive dependencies for known vulnerabilities, dependency confusion, and unexpected package changes.
  7. Build external dependencies in an isolated environment without Level-0 credentials, production network access, SSH keys, or deployment secrets.
  8. Run the final client with least privilege and expose only the credentials and administrative operations required for the current task.
  9. Monitor dependency digests and require security review whenever a remote artifact, lockfile, or Skill bundle changes.
  10. Document a trusted rollback version and immediately rotate the Level-0 token if dependency compromise is suspected.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (9)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 31)May include surrounding context.

md
- `SKILL.md`(本文件):全景说明与架构主文档(边界、部署、载荷模板、运维策略)。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 39)May include surrounding context.

md
- `SKILL.md`(本文件):全景说明与架构主文档(边界、部署、载荷模板、运维策略)。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

md
- `SKILL.md`(本文件):全景说明与架构主文档(边界、部署、载荷模板、运维策略)。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 197)May include surrounding context.

md
- `SKILL.md`(本文件):全景说明与架构主文档(边界、部署、载荷模板、运维策略)。

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file prominently designates Chinese-only operator materials and repeatedly frames the operator guidance in Chinese, such as the 'L0 操作者中文提要' and later '中文能力与硬性安全'. There is no visible opt-in, alternative language path, or justification that this skill is region-specific, which can conflict with language/locale choice policy.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 258)May include surrounding context.

md
2. 本机 **`v2/.deploy-env`**(由 `v2/.deploy-env.example` 复制):至少 **`ZENHEART_EC2_HOST`**;密钥默认 **`aws/zenheart-ec2.pem`** 或设 **`ZENHEART_EC2_KEY`**
3. 首次/密钥变更:SSH 上主机编辑 **`/opt/zenheart/services/v2_backend/.env`**(`DATABASE_URL`、`ADMIN_API_KEY`、`NEWS_MARKDOWN_ROOT`、SMTP、`SOCIAL_*`、`PUBLIC_WALL_*` 等 — **`v2/backend/.env.example`** 与下述指南)
4. 仅改前端:`v2/deploy-frontend.sh`(依赖本机 `v2/.deploy-env`)
5. 线上排障:`sudo systemctl status zenheart-v2-backend` · `sudo journalctl -u zenheart-v2-backend -f` · 服务器上 `curl -s http://127.0.0.1:8090/health`

### 权威文档(仓库路径)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The entire playbook is written as Chinese-only operational instruction, and there is no indication that users may choose another language or that the locale restriction is required for a region-specific compliance purpose. The policy requires flagging language or locale constraints when they are imposed without user opt-in or clear justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown guide explicitly states that it only retains a Chinese operator summary and presents the onboarding/read-first guidance in Chinese, without offering an alternative language or opt-in choice. That can violate a language/locale policy when users are required to consume a fixed language by default.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The summary is written entirely in Chinese, and the file does not state that the skill is region-specific or that users may choose another language. Under the policy, forcing a specific language without opt-in or justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.