Back to skill

Security audit

VPS Fusion Monster Server Test

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed VPS benchmark wrapper, but it automatically downloads and runs unverified native code and publishes detailed host/network results by default.

Install only if you are comfortable running an upstream native binary fetched at runtime. Prefer a constrained non-root environment, pass -upload=false unless you explicitly want public sharing, and treat generated reports as sensitive because they can include public IP, provider, route, port, and system fingerprints. The publisher should pin and verify downloads, remove plaintext mirrors, and make upload opt-in before this is treated as routine-risk.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T03 · Remote Payload Retrieval and Execution

Error
Location
run.sh:31
Finding

Unverified Native Binary Downloaded Through Mutable Third-Party Mirrors and Executed

Content
View full analysis
/dev/null; then CDN_OK="$cdn_url" ``` ```bash local gh_release_base="https://github.com/${GITHUB_REPO}/releases/download/v${version}" if [[ "$use_cn" == "true" ]]; then base_url="https://cnb.cool/oneclickvirt/ecs/-/releases/download/v${version}" else if check_cdn 2>/dev/null && [[ -n "$CDN_OK" ]]; then base_url="${CDN_OK}${gh_release_base}" else base_url="$gh_release_base" fi fi ``` ```bash local download_url="${base_url}/${zip_name}" local tmp_zip tmp_zip=$(mktemp "${bin_dir}/${BINARY_NAME}_XXXXXX.zip") if ! http_get "$download_url" "$tmp_zip" 2>/dev/null; then rm -f "$tmp_zip" if [[ "$use_cn" == "true" ]]; then if check_cdn 2>/dev/null && [[ -n "$CDN_OK" ]]; then download_url="${CDN_OK}${gh_release_base}/${zip_name}" else download_url="${gh_release_base}/${zip_name}" fi else download_url="${gh_release_base}/${zip_name}" fi tmp_zip=$(mktemp "${bin_dir}/${BINARY_NAME}_XXXXXX.zip") http_get "$download_url" "$tmp_zip" \ || { rm -f "$tmp_zip"; _fatal "All download sources failed"; } fi extract_zip "$tmp_zip" "$bin_dir" rm -f "$tmp_zip" chmod +x "$bin_path" ``` ```bash "$binary" -menu=false "$@" || true ``` ### Technical Analysis The Skill retrieves a precompiled native executable at runtime and immediately executes it. The archive can be obtained through mutable third-party proxy domains rather than exclusivel ...[truncated 2271 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
skill.json:169
Finding

Benchmark Results Are Configured for Public Upload by Default

Content
View full analysis
Remediation
View remediation

T01 · Skill Instruction Hijacking

Warning
Location
analyze.sh:243
Finding

Untrusted Benchmark Output Is Embedded Verbatim in AI Instructions

Content
View full analysis
/dev/null; then echo "$PROMPT" | llm elif command -v aichat &>/dev/null; then echo "$PROMPT" | aichat elif command -v ollama &>/dev/null; then MODEL="${OLLAMA_MODEL:-llama3}" echo "$PROMPT" | ollama run "$MODEL" fi fi ``` ### Technical Analysis The analyzer reads the complete contents of a user-selected benchmark file and inserts them directly into the same prompt that contains instructions for the AI model. ANSI removal does not sanitize natural-language instructions or establish a trusted data boundary. The result file can be influenced by: - A compromised remotely downloaded benchmark. - A malicious or modified comparison file. - Third-party network responses incorporated into benchmark output. - A local attacker able to replace the result file. An attacker can place text in the report instructing the model to ignore the surrounding analysis request, conceal warnings, fabricate scores, disclose other context, or invoke tools. The generated prompt does not clearly state that commands contained in the benchmark output are untrusted data that must never be followed. There is no direct shell command injection in the ...[truncated 1384 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (21)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 50)May include surrounding context.

md
| `SKILL.md` | 本文件 |

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill enables uploading test results to a public paste service by default, which can expose host, network, routing, and service information to third parties without informed consent. In the context of a VPS and network diagnostics tool, the collected data can reveal sensitive infrastructure details that materially increase privacy and reconnaissance risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README explicitly says the skill automatically downloads a precompiled binary from remote release infrastructure at runtime and executes it, but it does not warn users about the supply-chain and code-execution implications. In a skill ecosystem, this is especially dangerous because users may assume the uploaded package is what will run, while the real executable is fetched later from external mirrors or GitHub proxies.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README states that -upload is enabled by default and uploads results to a public paste service, but it does not prominently warn that benchmark output may contain sensitive infrastructure details such as IPs, routing, open mail ports, provider fingerprints, and geolocation-related data. Users may unknowingly publish reconnaissance data about their hosts or networks.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README presents the skill as a simple shell wrapper that downloads and executes a prebuilt binary, then later documents a much broader Go codebase with source builds, a local HTTP server, and library usage. This kind of contradiction is security-relevant because it can mislead reviewers and operators about the actual trust boundary, exposed interfaces, and deployment model, making risky functionality harder to assess and easier to smuggle in.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 261)May include surrounding context.

POST /run 示例

bash
curl -X POST http://localhost:8080/run \
  -H "Content-Type: application/json" \
  -d '{
    "categories": ["sysinfo", "cpu", "streaming"],

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill advertises shell-based execution behavior but does not declare any explicit tool scope or permissions boundary. In practice, this creates an authorization ambiguity: an agent or user may invoke shell actions, downloads, and file writes without a clearly documented least-privilege contract, increasing the chance of unintended command execution or unsafe environment access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill describes extensive benchmarking and network diagnostics, but it does not clearly warn users that execution triggers broad outbound probing to many third-party services and produces a local results file. This can expose IP reputation, system/network characteristics, and operational metadata, and may violate user expectations or local policy if run without informed consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The generated prompt instructs the downstream AI entirely in Chinese and mandates a specific Chinese report format, which effectively enforces a language choice on users. The file does not offer an opt-in, fallback, or documented region-specific justification for this locale constraint.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script embeds the complete cleaned test output into the generated AI prompt, and those results can contain sensitive operational data such as public IP addresses, ASN/provider details, location, routing paths, open mail ports, and service reachability. If the prompt is pasted into a third-party AI service or sent through a local tool backed by a remote model, that data may be disclosed outside the user's intended trust boundary.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Comparison mode amplifies the same disclosure risk by packaging two full result files into one prompt, increasing the volume and sensitivity of exposed infrastructure data. This can reveal relationships between multiple hosts, network topology clues, provider details, and comparative operational characteristics that may aid reconnaissance if shared with untrusted AI services.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file’s descriptive comments and usage text are written in Chinese, and the runtime status messages also continue in Chinese. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is clearly justified, which it is not here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script prints operational status and upload guidance entirely in Chinese, which means users interacting with the skill receive forced locale-specific messaging. The policy allows this only when the skill offers language choice or clearly documents a justified locale constraint, neither of which is present in this file.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
97% confidence
Finding

The script downloads a release-selected binary from external infrastructure and executes it, but performs no authenticity verification such as checksum or signature validation. This is especially dangerous in a skill/agent context because it turns network-delivered content into code execution; compromise of GitHub release assets, CDN paths, mirrors, or transport endpoints could lead to arbitrary code execution on the host.

Content

Scanner excerpt · run.sh (reported line 29)May include surrounding context.

sh
readonly GITHUB_REPO="oneclickvirt/ecs"
readonly BINARY_NAME="goecs"
readonly CACHE_DIR="${HOME}/.cache/clawchimera"
readonly GITHUB_API="https://api.github.com/repos/${GITHUB_REPO}/releases/latest"
# 上游 goecs.sh 使用的 CDN 前缀列表(同顺序)
readonly CDN_LIST="https://cdn0.spiritlhl.top/ http://cdn3.spiritlhl.net/ http://cdn1.spiritlhl.net/ http://cdn2.spiritlhl.net/"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script sends requests to third-party geolocation services to infer whether the host is in China without clearly warning the user that their public IP and request metadata will be disclosed. In an agent skill context, this is more sensitive because execution may be automated and users may not expect preflight privacy-affecting network calls unrelated to the core benchmark function.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest explicitly states that the first run will automatically download a precompiled binary from GitHub Releases/CDN and cache it locally, but it does not present a clear warning or require explicit consent for that outbound network activity. Automatic retrieval of executable code increases supply-chain and transparency risks, especially because users may not expect remote code acquisition during local skill execution.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest sets the default output language to zh, which forces a specific language unless the user notices and overrides it. Under the language/locale policy, locale-specific behavior should be opt-in or clearly offered as a user choice rather than imposed by default.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The usage examples describe the default full test as '中文' and only show English as an alternate via -l en, indicating a default language choice rather than asking the user to choose. This can be a locale-policy concern when the skill does not explicitly offer or request language preference before defaulting.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The usage comments describe the script as an AI analysis prompt generator, but they also advertise --call-ai and --copy, which cause the script to execute external local programs such as llm, aichat, ollama, xclip, xsel, or pbcopy. This is an intent-level divergence because the documentation frames the script primarily as prompt generation while the code includes active execution capabilities beyond simple output.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The introductory comments describe the script as automatically downloading the goecs binary from GitHub Releases and executing it. In addition to that, the code later contacts ipapi.co, ip-api.com, raw.githubusercontent.com, and multiple CDN endpoints to classify the user's network region and probe mirror availability, which is a broader behavior than the stated documentation suggests.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The usage examples and parameter documentation state that the default language is Chinese ('中文' / 'zh(默认)'), with English only available when users pass '-l en'. This imposes a language default rather than offering a user choice up front, which can violate language/locale neutrality expectations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.