Back to skill

Security audit

github-dns-helper

Security checks for vulnerabilities and agentic risk

Overview

The skill has a legitimate GitHub connectivity purpose, but it uses unsafe system-level DNS changes and unvalidated shell execution that users should review before installing.

Install only if you are comfortable with a tool that can change system-wide DNS behavior. Do not run the documented chown commands as written; keep hosts-file ownership at the operating-system default. Avoid custom hosts URLs, review any proposed hosts entries before applying them, and prefer a version that validates hostnames/IPs and uses argument-array subprocess calls or native HTTP fetching instead of shell=True.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:29
Finding

Persistent Weakening of System Hosts File Ownership

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/fix_github_dns.py:74
Finding

Shell Command Injection Through Custom Hosts URL

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
scripts/fix_github_dns.py:81
Finding

Untrusted Remote Hosts Data Written to System Name Resolution

Content
View full analysis
= 2: lines.append(line) return '\n'.join(lines) return None ``` The accepted remote content is subsequently incorporated into and written over the system hosts file: ```python github_hosts = fetch_single_host(url) if not github_hosts: print_status(f"从 {url} 获取失败,尝试下一个...", False) continue print(f"找到 GitHub hosts ({len(github_hosts.splitlines())} 条记录)") print("\n✍️ 步骤 4: 写入新的 hosts...") timestamp = datetime.datetime.now().astimezone().strftime("%Y-%m-%dT%H:%M:%S%z") timestamp = timestamp[:-2] + ":" + ti ...[truncated 3328 chars]
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (15)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

run_command is a generic shell execution wrapper that accepts arbitrary command strings and optionally prepends sudo, creating an unnecessary execution primitive inside a DNS-fix utility. Because later code passes interpolated data into this wrapper, the function enables arbitrary shell command execution beyond the tool’s stated purpose.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

Using subprocess.run(cmd, shell=True) turns tool parameters and internal variables into a shell-interpreted execution surface, enabling parameter abuse when any part of cmd is attacker controlled. In this skill, user-supplied URL parameters flow into command strings, so the risk is concrete rather than theoretical.

Content

Scanner excerpt · scripts/fix_github_dns.py (reported line 70)May include surrounding context.

python
def run_command(cmd, sudo=False):
    if sudo:
        cmd = f"sudo {cmd}"
    result = subprocess.run(cmd, shell=True, capture_output=True, text=True)
    return result.returncode, result.stdout, result.stderr

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
100% confidence
Finding

Custom hosts URLs supplied via -u/--urls are interpolated directly into curl -s --max-time 10 {url} and executed with shell=True, allowing an attacker to inject shell metacharacters and run arbitrary commands. This is especially dangerous because the script is intended to be run by users troubleshooting system networking and may be executed with administrative privileges to modify /etc/hosts or the Windows hosts file.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill invokes a local Python script and instructs the user to modify system files, which implies shell execution plus file read/write capability, yet it declares no tool scope or permission boundaries. In an agent environment, missing explicit tool restrictions increases the chance the skill can be run with broader-than-intended privileges and makes review/auditing harder.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The description and operating instructions are written entirely in Chinese and instruct the assistant in Chinese, with no indication that the user can choose another language. This can violate a language/locale policy when skills are expected to respect user language preference unless a locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
90% confidence
Finding

The skill instructs the user to run sudo chown on /etc/hosts, transferring ownership of a sensitive system file to the current user. Changing ownership of /etc/hosts weakens operating-system protections and can enable later unauthorized or accidental tampering with name resolution, which can redirect traffic to attacker-controlled destinations.

Content

Scanner excerpt · SKILL.md (reported line 32)May include surrounding context.

macOS:

bash
sudo chown $(whoami):staff /etc/hosts
sudo chmod 644 /etc/hosts

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
88% confidence
Finding

The instruction to run sudo chmod 644 /etc/hosts as part of making the file user-managed is risky in context because it normalizes privileged modification of a critical configuration file and may leave it writable through the preceding ownership change. Combined with the ownership transfer, this reduces defense-in-depth around DNS resolution on the host.

Content

Scanner excerpt · SKILL.md (reported line 33)May include surrounding context.

macOS:

bash
sudo chown $(whoami):staff /etc/hosts
sudo chmod 644 /etc/hosts

Linux:

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
88% confidence
Finding

The instruction to run sudo chmod 644 /etc/hosts as part of making the file user-managed is risky in context because it normalizes privileged modification of a critical configuration file and may leave it writable through the preceding ownership change. Combined with the ownership transfer, this reduces defense-in-depth around DNS resolution on the host.

Content

Scanner excerpt · SKILL.md (reported line 33)May include surrounding context.

macOS:

bash
sudo chown $(whoami):staff /etc/hosts
sudo chmod 644 /etc/hosts

Linux:

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
91% confidence
Finding

The Linux instruction to sudo chown /etc/hosts to the current user permanently delegates control of a critical networking file to a non-system account. If that account or any process running as that user is compromised, attackers can hijack DNS resolution for GitHub or other domains, enabling phishing, traffic interception, or update redirection.

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

Linux:

bash
sudo chown $(whoami):$(whoami) /etc/hosts
sudo chmod 644 /etc/hosts

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
88% confidence
Finding

The chmod command is not dangerous in isolation, but in this workflow it reinforces a persistent weakening of protections around /etc/hosts after ownership is changed. The more dangerous context is that the skill aims to make future edits possible without sudo, which removes an important friction/control point for altering system name resolution.

Content

Scanner excerpt · SKILL.md (reported line 39)May include surrounding context.

Linux:

bash
sudo chown $(whoami):$(whoami) /etc/hosts
sudo chmod 644 /etc/hosts

Windows:

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
88% confidence
Finding

The chmod command is not dangerous in isolation, but in this workflow it reinforces a persistent weakening of protections around /etc/hosts after ownership is changed. The more dangerous context is that the skill aims to make future edits possible without sudo, which removes an important friction/control point for altering system name resolution.

Content

Scanner excerpt · SKILL.md (reported line 39)May include surrounding context.

Linux:

bash
sudo chown $(whoami):$(whoami) /etc/hosts
sudo chmod 644 /etc/hosts

Windows:

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
89% confidence
Finding

Stating that after a one-time manual step the script can modify hosts entries without sudo indicates a design that intentionally bypasses normal privilege boundaries for a sensitive system file. In skill context, this is more dangerous because the whole purpose is to alter DNS resolution for GitHub, so any mistake or malicious update source could silently redirect developer traffic.

Content

Scanner excerpt · SKILL.md (reported line 47)May include surrounding context.

md
- 直接以管理员身份运行命令提示符或 PowerShell 即可

  ⚠️ **此操作必须由用户在系统终端中手动执行**
  执行后,脚本将不再需要 sudo 权限,可以免密码运行

### 仅检查连接状态

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
88% confidence
Finding

The function can prepend sudo to shell commands, which increases the blast radius of any command injection or misuse in downstream callers. In this script, the combination of privilege escalation capability and shell-based command construction makes exploitation materially more dangerous because successful injection could execute as root or prompt users to authorize privileged actions.

Content

Scanner excerpt · scripts/fix_github_dns.py (reported line 69)May include surrounding context.

python
def run_command(cmd, sudo=False):
    if sudo:
        cmd = f"sudo {cmd}"
    result = subprocess.run(cmd, shell=True, capture_output=True, text=True)
    return result.returncode, result.stdout, result.stderr

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
98% confidence
Finding

The helper executes shell commands with subprocess.run(..., shell=True), which is dangerous because multiple call sites build cmd from variable input, including user-provided URLs. In this skill’s context, a GitHub DNS repair tool has no legitimate need to expose a shell-interpreted command surface, so command injection can lead to arbitrary code execution under the invoking user and potentially elevated privileges when sudo is prepended.

Content

Scanner excerpt · scripts/fix_github_dns.py (reported line 70)May include surrounding context.

python
def run_command(cmd, sudo=False):
    if sudo:
        cmd = f"sudo {cmd}"
    result = subprocess.run(cmd, shell=True, capture_output=True, text=True)
    return result.returncode, result.stdout, result.stderr

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code file contains natural-language strings for the command description and help text that force a specific language/locale. The policy for SQP-3 applies to all file types, and there is no opt-in, fallback, or documented justification for limiting the interface to Chinese.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.