Back to skill

Security audit

AgentTunnel

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent agent messaging integration, but users should treat its URLs, secrets, and message contents as sensitive third-party service data.

Install only if you trust AgentTunnel and the npm package agt-tunnel. Do not send secrets, personal data, regulated data, or private operational context through conversations unless you are comfortable with that third-party service handling it. Treat join URLs, view URLs, and secrets like passwords because anyone with the right link or secret may be able to access or observe the conversation.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:29
Finding

Unpinned Global Installation of a Third-Party npm Package

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 8–10 and 29–31
Vulnerability Type: Unpinned third-party dependency installed globally
Risk Level: Medium

Vulnerable Code

yaml
install:
  - kind: node
    package: agt-tunnel
    bins: [agt]
bash
npm install -g agt-tunnel

Technical Analysis

The skill directs the environment to install the mutable latest release of the third-party agt-tunnel npm package without specifying an audited version or integrity hash. The global installation option (-g) places the package executable into the user's global npm environment.

Because the dependency's source code is not included in the audited project, its installation scripts and runtime behavior cannot be verified from this artifact. A compromised package release, maintainer account, or upstream distribution channel could cause a future installation to execute code different from the version originally reviewed. npm lifecycle scripts may execute during installation under the privileges of the user running npm.

Attack Path

  1. An attacker compromises the agt-tunnel npm package, its maintainer account, or its publication pipeline.
  2. The attacker publishes a malicious release under the existing package name.
  3. An agent follows SKILL.md and executes npm install -g agt-tunnel.
  4. npm resolves the unpinned dependency to the attacker-controlled release.
  5. Malicious npm lifecycle code executes during installation, or the installed agt executable runs malicious logic when invoked.
  6. The payload acts with the permissions of the installing user and may affect the user's global npm environment.

Impact Assessment

Successful exploitation could permit arbitrary code execution with the privileges of the user performing the installation. Depending on those privileges and the host configuration, the malicious package could access user-readable files and credentials, make network requests, alter the global npm environmen ...[truncated 177 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin agt-tunnel to a specific version that has undergone security review rather than installing the mutable latest release.
  • Verify the package using a lockfile and registry-provided integrity metadata.
  • Prefer a project-local installation over npm install -g to limit changes to the user's global tool environment.
  • Review the package source, transitive dependencies, and npm lifecycle scripts before authorizing installation.
  • Disable lifecycle scripts with --ignore-scripts where compatible with the package.
  • Execute the CLI in a sandbox or restricted environment with minimum filesystem, credential, and network access.
  • Establish an update-review process so package upgrades are explicitly assessed before the pinned version is changed.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs agents to exchange messages through AgentTunnel but does not clearly warn that conversation contents and associated metadata are sent to an external third-party service. This can cause users or agents to disclose sensitive prompts, secrets, or operational data under the mistaken assumption that the interaction is local or first-party.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation states that a view URL allows humans to follow the conversation, but it does not present this as a security warning or emphasize that possession of the URL may enable third-party observation. This increases the risk of unintended disclosure because users may share or store the URL insecurely without realizing it grants monitoring access.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 130)May include surrounding context.

md
## Additional Resources

- Human-facing website: https://agenttunnel.ai
- Full documentation: https://api.agenttunnel.ai/llms.txt

Static analysis

No suspicious patterns detected.