Back to skill

Security audit

Auto-Heal 通用守护

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent auto-healing service guard, but it needs review because it can repeatedly run arbitrary system repair and rollback commands, including privileged commands, with limited scoping or safety controls.

Review every services.json command as trusted code before use. Run the guard under the least-privileged account that can perform the needed action, protect the config file and parent directory from untrusted writes, avoid plaintext secrets in command strings, test manually before enabling cron, and add rate limits or alerting to prevent repeated unattended restarts or rollbacks.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/guard.sh:82
Finding

Arbitrary Command Execution Through Untrusted Service Configuration

Content
View full analysis
/dev/null 2>&1 return $? ;; *) log_warn "未知检测类型: $check_type" return 1 ;; esac return 1 } # 执行修复 do_fix() { local name="$1" local fix_cmd="$2" log_info "[$name] 执行修复..." eval "$fix_cmd" 2>&1 | while read line; do log " $line" done } # 执行回滚 do_rollback() { local name="$1" local rollback_cmd="$2" local backup_dir="$3" # 自动备份(如果指定了备份目录) if [[ -n "$backup_dir" && -f "$CONFIG_FILE" ]]; then mkdir -p "$backup_dir" # 这里需要根据实际情况备份对应服务的配置文件 # 通用回滚依赖用户自定义 rollback 命令 fi if [[ -z "$rollback_cmd" ]]; then log_warn "[$name] 未定义回滚命令,跳过" return 1 fi log_warn "[$name] 执行回滚..." eval "$rollback_cmd" 2>&1 | while read line; do log " $line" done } ``` The affected values originate directly from the configuration at `scripts/guard.sh:153-155`: ```bash local fix_cmd=$(echo "$service" | jq -r '.fix') local rollback_cmd=$(echo "$service" | jq -r '.rollback // empty') local timeout=$(echo "$service" | jq -r '.timeout // 5') ``` The custom health-check command similarly comes from `.check.command` in the supplied JSON service object. ### Technical Analysis The script treats JSON configuration fields as shell source code and evaluates them with `eval`. Consequently, shell operators, command substitutions, redirections, pipelines, variable expansions, and chained commands contained in the configuration are interpreted by the shell. The vulnerable execution sinks cover three paths: 1. A custom `cmd` health check. 2. The `fix` ac ...[truncated 2748 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
references/examples.md:88
Finding

Plaintext Database Password Embedded in Configuration Example

Content
View full analysis
/dev/null" ``` ### Technical Analysis The example encourages users to place a MySQL password directly in a JSON configuration and pass it to `mysqladmin` through the `-p` command-line option. Although `secret` is an example placeholder rather than a confirmed production credential, users may follow the pattern by substituting a real password. The resulting credential would be stored in plaintext in `services.json`. Depending on the operating system and process visibility settings, it may also be exposed while the health-check process is running. Copies can additionally propagate into backups, support bundles, source-control history, or other systems that collect configuration files. Using the database root account further magnifies the potential consequences if an operator adopts the example literally. ### Attack Path A concrete exposure path is: 1. An operator copies the documented example. 2. The operator replaces `secret` with a real database password and leaves the username as `root`. 3. The plaintext credential is saved in `services.json`. 4. A local user, backup operator, repository reader, support-bundle recipient, or compromised process obtains access to that file. 5. Alternatively, a local observer obtains the password from process information while `mysqladmin` is running, where platform permissions allow such inspection. 6. The exposed credential is then used to authenticate to MySQL from an accessible local or remote endpoint. ### Impact Assessment The impact depends on the permissions of the credential and database network exposure. If the documented root-account pattern is used, disclosure may permit complete control over the affected MySQL instance, including ...[truncated 269 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (14)

Chaining Abuse

High
Category
Tool Misuse
Confidence
76% confidence
Finding

The cleanup pipeline uses ls output piped into xargs rm, which is brittle and can behave unsafely with unusual filenames, glob edge cases, or names beginning with dashes. In this context, backup_dir and service_name are configuration-derived, so malformed or attacker-controlled values could lead to deletion of unintended files during retention cleanup.

Content

Scanner excerpt · scripts/guard.sh (reported line 141)May include surrounding context.

sh
log_info "[$service_name] 备份已保存: $backup_file"
        
        # 保留最近10份
        ls -1t "$backup_dir"/${service_name}_*.json 2>/dev/null | tail -n +11 | xargs -r rm -f
    fi
}

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly promotes automatic detect-repair-rollback behavior for arbitrary services, but the description does not warn users that configured fix and rollback actions may execute privileged, state-changing, or destructive shell commands. In a self-healing framework, that omission materially increases the chance of unsafe deployment because operators may enable autonomous remediation without understanding that it can restart services, overwrite configs, or trigger rollback actions without manual approval.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The cron example documents unattended recurring execution every 5 minutes, but it does not clearly warn that the skill will repeatedly perform autonomous system modifications whenever checks fail. This makes the pattern more dangerous because a bad health check, transient outage, or misconfigured remediation command could cause repeated restart loops, config overwrites, or rollback churn without human supervision.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Across the examples, the skill documentation demonstrates automatic execution of commands such as systemctl restart, docker restart, pm2 restart, cp overwrites, and sudo systemctl restart, yet it does not disclose the operational risk of service interruption or unintended changes. In markdown skill documentation, users should be warned when behavior may affect system integrity or service availability.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

md
"name": "myapi",
      "check": {
        "type": "http",
        "url": "https://api.example.com/health",
        "expected": "200"
      },
      "fix": "systemctl restart myapi && sleep 3",

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/examples.md (reported line 31)May include surrounding context.

md
"name": "myapi",
      "check": {
        "type": "http",
        "url": "https://api.example.com/health",
        "expected": "200"
      },
      "fix": "systemctl restart myapi && sleep 3",

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/examples.md (reported line 185)May include surrounding context.

md
"name": "myapi",
      "check": {
        "type": "http",
        "url": "https://api.example.com/health",
        "expected": "200"
      },
      "fix": "systemctl restart myapi && sleep 3",

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file includes examples that overwrite configuration files and restart services as part of automated fixes and rollbacks, but the surrounding documentation does not warn users that these actions can modify system state or impact availability. For markdown files, safety-relevant behavior that affects user data or system integrity should be accompanied by an explicit warning.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/examples.md (reported line 150)May include surrounding context.

md
"type": "cmd",
        "command": "curl -s http://localhost:8080 > /dev/null"
      },
      "fix": "sudo systemctl restart actions-runner",
      "rollback": "sudo systemctl restart actions-runner",
      "timeout": 5
    }

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/examples.md (reported line 151)May include surrounding context.

md
"type": "cmd",
        "command": "curl -s http://localhost:8080 > /dev/null"
      },
      "fix": "sudo systemctl restart actions-runner",
      "rollback": "sudo systemctl restart actions-runner",
      "timeout": 5
    }

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script automatically executes shell-based fix and rollback commands from the configuration using eval, without confirmation, allowlisting, or isolation. In this skill context, the config effectively becomes code execution input, so a malicious or compromised services.json entry can run arbitrary commands with the script's privileges and cause destructive changes during routine health checks.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The natural-language content of the skill file is presented entirely in Chinese, which can impose a language constraint on users without any opt-in or stated regional justification. The policy requires avoiding forced language or locale restrictions unless users are given a choice or the constraint is clearly documented.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script's human-facing comments, usage text, and log/error messages are written in Chinese only, which imposes a specific language on users without offering a choice or documenting a region-specific requirement. This matches the language/locale policy violation category for natural-language content in code files.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The comment at L106 says an automatic backup will occur if a backup directory is specified, but the code only creates the directory and includes comments saying real backup behavior depends on user-defined rollback logic. This is an intent/documentation contradiction rather than a mere omission because the comment explicitly describes behavior that is not implemented.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.