Back to skill

Security audit

ssh-full

Security checks for vulnerabilities and agentic risk

Overview

This SSH automation skill is mostly transparent about its purpose, but the full edition has real credential-exposure and local command-injection risks that should be reviewed before installation.

Prefer the base key-only edition unless you specifically need password authentication or sudo. Do not use the sudo-password flow or ssh-keys.sh store with sensitive keys until the argv/JSON secret exposure issues are fixed, and avoid exporting private keys into environment variables. Use dedicated least-privilege SSH accounts and single-purpose keys, verify host keys, and require explicit approval for every mutating or privileged remote command.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/ssh-run-native.sh:353
Finding

Plaintext sudo password exposed through command arguments and JSON output

Content
View full analysis
' | sudo -S -p '' -- sh -c "$(echo '' | base64 -d)" ENCODED_CMD=$(printf '%s' "$REMOTE_COMMAND" | base64 -w0) REMOTE_COMMAND="echo '${SUDO_PASS}' | sudo -S -p '' -- sh -c \"\$(echo '${ENCODED_CMD}' | base64 -d)\"" else ORIGINAL_COMMAND="$REMOTE_COMMAND" fi # Dangerous command check if is_dangerous_command "$REMOTE_COMMAND" && [[ "$CONFIRM_DANGEROUS" -ne 1 ]]; then python3 - "$HOST" "$REMOTE_COMMAND" <<'PY' import json, sys host, cmd = sys.argv[1:] print(json.dumps({ "success": False, "exit_code": 99, "dangerous": True, "heuristic_match": True, "error": "Command looks mutating or destructive. Re-run with --confirm-dangerous only after explicit user approval.", "host": host, "command": cmd, })) PY exit 99 fi ``` The wrapped command is subsequently supplied as a process argument: ```bash $SSH_BIN "${SSH_ARGS[@]}" -G "$TARGET" >"$RESOLVED_FILE" 2>/dev/null RESOLVE_EXIT=$? $SSH_BIN "${SSH_ARGS[@]}" "$TARGET" "$REMOTE_COMMAND" >"$STDOUT_FILE" 2>"$STDERR_FILE" EXIT_CODE=$? ``` ### Technical Analysis The resolved sudo password is interpolated directly into `REMOTE_COMMAND`. This causes the plaintext credential to cross multiple unsafe boundaries: 1. The password becomes part of the local `ssh` process argument vector. 2. It may become visible to process inspection, monitoring, crash diagnostics, audit tooling, or other users with sufficient `/proc` access. 3. If `--confirm-dangerous` is absent, the dangerous-command rejection serializes the wrapped command into the JSON `command` field, directly returning the password through stdout. 4. The SSH server receives the command as text, potentially exposing it through server ...[truncated 1405 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/ssh-run.sh:126
Finding

Local command injection through eval of SSH configuration values

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/ssh-keys.sh:95
Finding

Private SSH key exposed in vault backend process arguments

Content
View full analysis
`. 2. The script reads and base64-encodes the private key. 3. Bash expands the full encoded key into the vault resolver’s argument vector. 4. A local observer, monitoring agent, malicious wrapper, or sufficiently privileged process captures the backend argv. 5. The observer base64-decodes the captured value and obtains the original private key. ### Impact Assessment The captured key can authenticate to every host and account that trusts it until the key is revoked. Consequences can include unauthorized remote access, data theft, command execution ...[truncated 143 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
references/server-to-server-rsync.md:94
Finding

Actionable workflow copies a private SSH key onto a remote host

Content
View full analysis
-o StrictHostKeyChecking=yes" \ /path/source/ \ user@:/path/dest/' # 4. Remove the temporary key and verify ssh user@server-a 'shred -u /dev/shm/transfer_key && echo "CLEANUP VERIFIED"' ``` ### Technical Analysis The document marks this workflow as deprecated and last-resort, but it remains directly actionable. It copies private authentication material to server A so that server A can authenticate to server B. File permissions and `/dev/shm` limit incidental disk persistence but do not protect the key from privileged processes, the remote account itself, host compromise, memory inspection, backups, or capture while present. Deleting the file cannot revoke copies already obtained by an attacker. Network failure or process interruption can also prevent cleanup. This behavior exceeds the minimum privilege necessary for server-to-server transfer because client-mediated transfer and jump-host techniques can avoid placing reusable private credentials on either remote source host. ### Attack Path 1. The Agent follows the documented last-resort transfer workflow. 2. A private key is copied from the trusted client to `/dev/shm/transfer_key` on server A. 3. A compromised process, privileged user, or attacker controlling server A reads or duplicates the key. 4. The intended cleanup deletes only the original file. 5. The attacker uses th ...[truncated 497 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/ssh-run-native.sh:58
Finding

Dangerous-command confirmation gate is bypassable through unrecognized mutating commands

Content
View full analysis
])', r'(?:sh\s+-c|bash\s+-c)\s', r'chpasswd\s|passwd\s|usermod\s|groupmod\s|useradd\s|userdel\s', r'(?:>>?\s+\S+(?:\s|$)|>\||:>|echo\s+.*[>]|printf\s+.*[>])', r'(?:tee\s|truncate\s|dd\s|mkfs(?!\.\w+)|mkfs\.|fdisk\s|pvcreate\s|vgremove\s|lvremove\s)', r'(?:iptables\s|ufw\s|firewall-cmd\s|nmcli\s)', r'(?:eval\s|evals\s)', ] for p in patterns: if re.search(p, cmd): sys.exit(0) sys.exit(1) PY } ``` The authorization decision relies on that pattern list: ```bash if is_dangerous_command "$REMOTE_COMMAND" && [[ "$CONFIRM_DANGEROUS" -ne 1 ]]; then python3 - "$HOST" "$REMOTE_COMMAND" <<'PY' import json, sys host, cmd = sys.argv[1:] print(json.dumps({ "success": False, "exit_code": 99, "dangerous": True, "heuristic_match": True, "error": "Command looks mutating or destructive. Re-run with --confirm-dangerous only after explicit user approval.", "host": host, "command": cmd, })) PY exit 99 fi ``` ### Technical Analysis The Skill’s documented policy requires confirmation before state-changing operations, but enforcement de ...[truncated 1531 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (135)

Credential Access

High
Category
Privilege Escalation
Confidence
93% confidence
Finding

The example export SSH_KEY="$(cat ~/.ssh/id_rsa)" encourages loading an entire private key into an environment variable. Environment variables are widely exposed to child processes, crash dumps, debugging interfaces, CI logs, and sometimes other local observers, making this a poor secret-handling pattern for private keys.

Content

Scanner excerpt · SKILL.md (reported line 62)May include surrounding context.

Claude Code / Codex / Generic LLM

bash
# No vault — use env vars or key files:
export SSH_KEY="$(cat ~/.ssh/id_rsa)"
ssh-run.sh --host my-server --user ubuntu --key ~/.ssh/id_rsa -- 'uptime'

# Or with password (requires SSH_EXECUTOR_ALLOW_DANGEROUS=1):

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 132)May include surrounding context.

md
| `terminal` | Bash scripts (`ssh-run.sh`, `ssh-keys.sh`, `ssh-run-native.sh`) | SSH command execution |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 205)May include surrounding context.

md
| `terminal` | Bash scripts (`ssh-run.sh`, `ssh-keys.sh`, `ssh-run-native.sh`) | SSH command execution |

Chaining Abuse

High
Category
Tool Misuse
Confidence
78% confidence
Finding

The password piping pattern creates a shell-mediated command chain around a privileged operation. Even if used for benign reasons, chaining secrets through echo | sudo makes the security of the sudo step depend on shell parsing, wrapper behavior, and logging hygiene, which broadens the attack surface for leakage or misuse.

Content

Scanner excerpt · SKILL.md (reported line 266)May include surrounding context.

md
**Security:**
- Password resolved in RAM, never on disk
- Sent via `echo '<pass>' | sudo -S -p ''` — password never appears on the command line (`ps`)
- `-p ''` suppresses sudo password prompt (avoids stderr pollution)
- Original command is base64-encoded to avoid quote escaping issues
- `--sudo` automatically enables `--confirm-dangerous` (no extra flag needed)

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · SKILL.md (reported line 491)May include surrounding context.

md
The skill is split into two editions, built from the same source via `build.sh`:

| Edition | Package | Auth | Sudo | Lines |
|---------|---------|------|------|-------|
| **Base** | `ssh-executor-<ver>.zip` | Key only | No | 270 |
| **Full** | `ssh-executor-full-<ver>.zip` | Key + password | Yes | 481 |

Privileged Container / Container Escape

High
Category
Privilege Escalation
Confidence
85% confidence
Finding

Potential security issue detected. Manual review is recommended.

Content

Scanner excerpt · references/docker-diagnostics-without-cli.md (reported line 38)May include surrounding context.

Compare the process network namespace with the host's:

bash
host_ns=$(readlink /proc/1/ns/net)
container_ns=$(readlink /proc/<PID>/ns/net)
if [ "$host_ns" = "$container_ns" ]; then
  echo "network_mode: host"

Privileged Container / Container Escape

High
Category
Privilege Escalation
Confidence
85% confidence
Finding

Potential security issue detected. Manual review is recommended.

Content

Scanner excerpt · references/docker-diagnostics-without-cli.md (reported line 159)May include surrounding context.

md
Diagnosis performed:
1. `cat /proc/<PID>/cmdline` → confirmed mysqld with MariaDB args
2. `readlink /proc/<PID>/ns/net == readlink /proc/1/ns/net` → network_mode host
3. `ss -tlnp` → **zero** port 3306 on any IP
4. `cat /etc/mysql/mysql.conf.d/mysqld.cnf` → bind-address = 127.0.0.1 on host
   (but this is the host config, not the container's)

Privileged Container / Container Escape

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Potential security issue detected. Manual review is recommended.

Content

Scanner excerpt · references/docker-diagnostics-without-cli.md (reported line 176)May include surrounding context.

md
| Problem | Cause | Solution |
|----------|-------|---------|
| `ls /proc/PID/fd/` empty | PID runs as different UID (e.g. 999 = mysql) | Try `sudo ls` or use other techniques |
| `nsenter` access denied | No CAP_SYS_ADMIN permission | Do not use nsenter without sudo |
| `ip neigh` shows FAILED | Container with network_mode host (no dedicated IP) | Container shares host IP; look for port on host |
| Bridge linkdown but IP configured | Docker network without containers (created but unused) | Check which bridge has REACHABLE/STALE traffic |
| `docker logs` unavailable | No docker CLI access | Only option: `journalctl` or process logs in datadir |

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · references/safety.md (reported line 33)May include surrounding context.

md
- deletes, rotates, or truncates data (`truncate`, `dd`, logrotate actions)
- changes containers, databases, firewalls, or network state (`docker rm|down|kill`, `kubectl delete`, `iptables`, `ufw`, `firewall-cmd`, `ip link set`, `ip addr add|del`, `nmcli`)
- writes to disk or pipes output to a file (`>`, `>>`, `| tee`, `dd`)
- executes code on the remote host that was not explicitly reviewed (`curl | bash`, `wget -O- | sh`, `eval`, `source`)

**When in doubt, treat the command as dangerous and ask for confirmation.**

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · references/safety.md (reported line 33)May include surrounding context.

md
- deletes, rotates, or truncates data (`truncate`, `dd`, logrotate actions)
- changes containers, databases, firewalls, or network state (`docker rm|down|kill`, `kubectl delete`, `iptables`, `ufw`, `firewall-cmd`, `ip link set`, `ip addr add|del`, `nmcli`)
- writes to disk or pipes output to a file (`>`, `>>`, `| tee`, `dd`)
- executes code on the remote host that was not explicitly reviewed (`curl | bash`, `wget -O- | sh`, `eval`, `source`)

**When in doubt, treat the command as dangerous and ask for confirmation.**

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · SKILL.md (reported line 386)May include surrounding context.

md
| 2 | Credential Mismanagement | 99% | Header forbids passwords but docs instruct storage | Header clarified: "passwords for automation may be stored in Vaultwarden with explicit approval" |
| 3 | Key Exfiltration | 99% | Rsync workflow copies private key to remote server | server-to-server-rsync.md deprecated; ForwardAgent preferred |
| 4 | Host-Key Bypass | 99% | AutoAddPolicy in Python, accept-new in native | Default RejectPolicy (Python), StrictHostKeyChecking=yes (native), accept-new removed |
| 5 | Destructive Commands | 94% | sudo find ... -delete without confirmation | Warning banner in remote-backup-cleanup.md |
| 6 | Undeclared MCP | 92% | Shell, file, env-var access undeclared | MCP Permissions Declaration section added |

## Findings Fixed in v2.2.1 (Medium Severity)

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · references/security-audit-2026-07-clawhub.md (reported line 15)May include surrounding context.

md
| 2 | Credential Mismanagement | 99% | Header forbids passwords but docs instruct storage | Header clarified: "passwords for automation may be stored in Vaultwarden with explicit approval" |
| 3 | Key Exfiltration | 99% | Rsync workflow copies private key to remote server | server-to-server-rsync.md deprecated; ForwardAgent preferred |
| 4 | Host-Key Bypass | 99% | AutoAddPolicy in Python, accept-new in native | Default RejectPolicy (Python), StrictHostKeyChecking=yes (native), accept-new removed |
| 5 | Destructive Commands | 94% | sudo find ... -delete without confirmation | Warning banner in remote-backup-cleanup.md |
| 6 | Undeclared MCP | 92% | Shell, file, env-var access undeclared | MCP Permissions Declaration section added |

## Findings Fixed in v2.2.1 (Medium Severity)

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · references/security-audit-2026-07-clawhub.md (reported line 24)May include surrounding context.

md
|---|----------|-----------|---------|-----|
| 7 | Temp Key Cleanup | 93-95% | trap EXIT only, kill -9 bypasses | trap EXIT INT TERM HUP + shred -u |
| 8 | restore-to-file Path | 92% | Writes to any caller-specified path | Path validation: rejects /etc, /boot, /sys, /proc, /dev, /run; warns non-tmp |
| 9 | Missing User Warning | — | No warning on --host-key-checking no | Explicit stderr MITM warning |
| 10 | Pass-through Bug | — | --host-key-checking ignored by Python backend | ssh-run.sh now captures and passes to ssh-client.py |
| 11 | SSL/TLS | — | check_hostname=False without caveat | "Only safe on trusted local networks" |

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · references/security-audit-2026-07-clawhub.md (reported line 26)May include surrounding context.

md
| 8 | restore-to-file Path | 92% | Writes to any caller-specified path | Path validation: rejects /etc, /boot, /sys, /proc, /dev, /run; warns non-tmp |
| 9 | Missing User Warning | — | No warning on --host-key-checking no | Explicit stderr MITM warning |
| 10 | Pass-through Bug | — | --host-key-checking ignored by Python backend | ssh-run.sh now captures and passes to ssh-client.py |
| 11 | SSL/TLS | — | check_hostname=False without caveat | "Only safe on trusted local networks" |

## Confirmed Safe (No Action Needed)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/server-to-server-rsync.md (reported line 35)May include surrounding context.

  1. The destination directory is writable by the user on server B:
    bash
    ssh -p <PORT> user@server-b 'touch /path/dest/.test_write && rm /path/dest/.test_write' 2>&1
    
    If it fails (Permission denied):
    • Try sudo mkdir -p /path/dest/ (some servers have NOPASSWD)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/server-to-server-rsync.md (reported line 89)May include surrounding context.

/tmp/staging/ user@server-b:/path/dest/

Clean up staging

rm -rf /tmp/staging

text

⚠️ **Downside:** all traffic passes through the client twice.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/server-to-server-rsync.md (reported line 89)May include surrounding context.

/tmp/staging/ user@server-b:/path/dest/

Clean up staging

rm -rf /tmp/staging

text

⚠️ **Downside:** all traffic passes through the client twice.

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 352)May include surrounding context.

md
## 1. UserKnownHostsFile /dev/null Nullifies StrictHostKeyChecking

**Symptom:** `Host key verification failed` (exit 255) even though the host key is in `~/.ssh/known_hosts`.

**Root cause:** `~/.ssh/config` has `UserKnownHostsFile /dev/null` — SSH effectively has no trust store. When our skill sets `StrictHostKeyChecking=yes` (hardening v2.2.0), strict checking fails because there's nothing to check against.

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 392)May include surrounding context.

md
## 1. UserKnownHostsFile /dev/null Nullifies StrictHostKeyChecking

**Symptom:** `Host key verification failed` (exit 255) even though the host key is in `~/.ssh/known_hosts`.

**Root cause:** `~/.ssh/config` has `UserKnownHostsFile /dev/null` — SSH effectively has no trust store. When our skill sets `StrictHostKeyChecking=yes` (hardening v2.2.0), strict checking fails because there's nothing to check against.

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 393)May include surrounding context.

md
## 1. UserKnownHostsFile /dev/null Nullifies StrictHostKeyChecking

**Symptom:** `Host key verification failed` (exit 255) even though the host key is in `~/.ssh/known_hosts`.

**Root cause:** `~/.ssh/config` has `UserKnownHostsFile /dev/null` — SSH effectively has no trust store. When our skill sets `StrictHostKeyChecking=yes` (hardening v2.2.0), strict checking fails because there's nothing to check against.

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/safety.md (reported line 17)May include surrounding context.

md
## 1. UserKnownHostsFile /dev/null Nullifies StrictHostKeyChecking

**Symptom:** `Host key verification failed` (exit 255) even though the host key is in `~/.ssh/known_hosts`.

**Root cause:** `~/.ssh/config` has `UserKnownHostsFile /dev/null` — SSH effectively has no trust store. When our skill sets `StrictHostKeyChecking=yes` (hardening v2.2.0), strict checking fails because there's nothing to check against.

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/testing-pitfalls-2026-07-23.md (reported line 7)May include surrounding context.

md
## 1. UserKnownHostsFile /dev/null Nullifies StrictHostKeyChecking

**Symptom:** `Host key verification failed` (exit 255) even though the host key is in `~/.ssh/known_hosts`.

**Root cause:** `~/.ssh/config` has `UserKnownHostsFile /dev/null` — SSH effectively has no trust store. When our skill sets `StrictHostKeyChecking=yes` (hardening v2.2.0), strict checking fails because there's nothing to check against.

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/troubleshooting-field-notes.md (reported line 49)May include surrounding context.

md
## 1. UserKnownHostsFile /dev/null Nullifies StrictHostKeyChecking

**Symptom:** `Host key verification failed` (exit 255) even though the host key is in `~/.ssh/known_hosts`.

**Root cause:** `~/.ssh/config` has `UserKnownHostsFile /dev/null` — SSH effectively has no trust store. When our skill sets `StrictHostKeyChecking=yes` (hardening v2.2.0), strict checking fails because there's nothing to check against.

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/ssh-client.py (reported line 239)May include surrounding context.

python
## 1. UserKnownHostsFile /dev/null Nullifies StrictHostKeyChecking

**Symptom:** `Host key verification failed` (exit 255) even though the host key is in `~/.ssh/known_hosts`.

**Root cause:** `~/.ssh/config` has `UserKnownHostsFile /dev/null` — SSH effectively has no trust store. When our skill sets `StrictHostKeyChecking=yes` (hardening v2.2.0), strict checking fails because there's nothing to check against.

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 379)May include surrounding context.

Fix applied: In ssh-run-native.sh, when HOST_KEY_CHECKING=yes, the script now forces:

text
-o UserKnownHostsFile=${HOME}/.ssh/known_hosts

This overrides the /dev/null from the SSH config and points to the real known_hosts file. A touch ensures the file exists (SSH refuses nonexistent UserKnownHostsFile paths).

Static analysis

No suspicious patterns detected.