Back to skill

Security audit

Lightweight Host Intrusion Detection and Log Analysis System (Mini-HIDS)

Security checks for vulnerabilities and agentic risk

Overview

Mini-HIDS is a coherent defensive tool, but it can automatically make privileged firewall changes from log data that may be ambiguous or spoofable.

Install only after reviewing the configuration for your server. Pin the source you install, set trusted IPs and web roots narrowly, avoid automatic web-log bans behind proxies unless client identity is trustworthy, and treat the MCP server as a privileged local control plane because it can change firewall state.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
hids_common.py:359
Finding

Untrusted access-log client identity can trigger privileged firewall bans

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
hids_common.py:403
Finding

Unbounded web-root and alert-log reads can exhaust process memory

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 63)May include surrounding context.

After your agent has packaged the project as a skill, adjust config.json for the target server and start the daemon:

bash
sudo python3 mini_hids.py

Use With AI Agents

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This helper executes firewall management commands via subprocess and is later used to add DROP rules, delete rules, and invoke fail2ban ban/unban actions. The file contains no confirmation prompt, print/log disclosure, or explanatory comment/docstring warning that it will modify host firewall state, which is a safety-critical operation.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · hids_common.py (reported line 177)May include surrounding context.

python
self.backend = detect_firewall(backend)

    def _run(self, command, check=True):
        return subprocess.run(
            command,
            check=check,
            stdout=subprocess.DEVNULL,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · hids_common.py (reported line 185)May include surrounding context.

python
)

    def _capture(self, command):
        return subprocess.run(
            command,
            check=False,
            stdout=subprocess.PIPE,

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code returns multiple hard-coded Chinese response messages such as '封禁失败', '已成功封禁', '无效的 IP 地址', and '已成功解封'. The file provides no opt-in, locale selection, or justification that the skill is intentionally region-specific, which is a natural-language locale policy violation under the stated rules.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Several user-visible error strings are hard-coded in Chinese, such as the argument validation messages returned to callers. This imposes a specific language on all users of the skill and does not provide opt-in, fallback, or documentation that the tool is intentionally Chinese-only.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module description is entirely in Chinese and presents the skill as a general-purpose Mini-HIDS rather than a region-specific tool. User-facing runtime messages throughout the file are also hard-coded in Chinese, with no indication that language selection is optional or configurable, which violates the language/locale policy criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This Python test file contains multiple natural-language strings that enforce Chinese alert labels such as "Web攻击", "SSH暴力破解", and other Chinese log message formats. Under the stated policy, forcing a specific language without user opt-in or documented justification is a locale-policy violation, and the file does not indicate that this is a region-specific or opt-in behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill returns user-facing status messages in Chinese and also depends on Chinese alert labels/messages when parsing alerts. This imposes a specific language/locale without offering user choice or documenting a justified locale restriction, which matches the language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This file is an SVG image, so only SQP-3 applies. The visible title, description, and labels are all in Chinese, and the file does not indicate that this locale is optional or specifically required for a region-scoped skill, which can conflict with language/locale choice policies.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.