Back to skill

Security audit

TunnelProxy

Security checks for vulnerabilities and agentic risk

Overview

This skill openly gives a cloud agent broad control over the user's computer, but the access is too powerful and under-scoped for routine installation.

Install only in an isolated disposable VM or container under a dedicated low-privilege account, never on a personal or work machine with sensitive files, credentials, browser sessions, or internal-network access. Do not expose it publicly unless you add your own TLS, authentication, allowlists, logging, and per-action approval controls.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T09 Β· Insecure Skill Coding Practices

Error
Location
scripts/tunnel_login.py:5
Finding

Authentication Tokens and Remote-Control Traffic Are Transmitted Over Plaintext Channels

Content
View full analysis
:8080/api/session", json={"token": token}) port = resp.json()["port"] s = socket.socket() s.connect(("", port)) s.send(b"ls -la\n") print(s.recv(4096).decode()) ``` ### Technical Analysis The bearer token is placed in an HTTP request without TLS. The subsequent PTY connection uses a raw TCP socket without transport encryption or server authentication. As a result, the authentication token, commands, and returned terminal output may be observed or modified by any party with a network-adjacent or intermediary position. The documentation recommends optional public exposure through FRP, increasing the likelihood that this traffic crosses untrusted networks. A random, short-lived PTY port does not provide confidentiality or reliable authentication. Once the port is returned, the PTY connection itself performs no additional authentication in the included client. Because the token authorizes creation of a remote shell session, interception has substantially greater impact than disclosure of an ordinary API key. ### Attack Path 1. The user exposes the TunnelProxy HTTP endpoint through FRP, a public interface, or another routed network. 2. The Agent ...[truncated 1287 chars]
Remediation
View remediation

T05 Β· Unauthorized Access and Privilege Escalation

Error
Location
scripts/http_transfer.py:35
Finding

File Listing, Download, and Upload Requests Lack Authentication and Authorization

Content
View full analysis
str: url = self.base_url + "/" + path.lstrip("/") r = urllib.request.urlopen(url, timeout=self.timeout) return r.read().decode("utf-8", errors="replace") def download(self, remote_path: str, local_path: str) -> int: url = self.base_url + "/" + remote_path.lstrip("/") r = urllib.request.urlopen(url, timeout=self.timeout) data = r.read() pathlib.Path(local_path).parent.mkdir(parents=True, exist_ok=True) with open(local_path, "wb") as f: f.write(data) return len(data) def upload(self, local_path: str) -> str: filename = os.path.basename(local_path) with open(local_path, "rb") as f: data = f.read() boundary = "----TunnelProxyBoundary" body = ( f"--{boundary}\r\n" f'Content-Disposition: form-data; name="file"; filename="{filename}"\r\n' f"Content-Type: application/octet-stream\r\n\r\n" ).encode() + data + f"\r\n--{boundary}--\r\n".encode() req = urllib.request.Request( self.base_url + "/upload", data=body, method="POST", ) req.add_header("Content-Type", f"multipart/form-data; boundary={boundary}") try: r = urllib.request.urlopen(req, timeout=self.timeout) return r.read().decode("utf-8", errors="replace").strip() except urllib.error.HTTPError as e: raise RuntimeError(f"上传倱θ΄₯ HTTP {e.code}: {e.read().decode()[:200]}") ``` The protocol explicitly describes the exposed operations: ```markdown | GET | `/` | List root directory (HTML) | | GET | `/{path}` | Download file | | POST | `/upload` | Upload file (expects raw binary body) | ``` ### Technical Analysis None of the file-operation methods sends ` ...[truncated 2185 chars]
Remediation
View remediation

T05 Β· Unauthorized Access and Privilege Escalation

Error
Location
references/TIPS.md:151
Finding

Unrestricted Remote Shell Breaks Least-Privilege Boundaries

Content
View full analysis
)) s.send(b"python3 /uploads/my_script.py\n") result = s.recv(4096).decode() ``` The included login script demonstrates direct command execution: ```python s = socket.socket() s.connect((host, port)) s.send(b"ls -la\n") print(s.recv(4096).decode()) s.close() ``` The declared architecture explicitly provides both an HTTP command endpoint and an interactive PTY: ```text POST /api/exec β†’ POST /api/heartbeat β†’ GET /api/result/:task_id POST /api/session β†’ get random port β†’ nc ``` ### Technical Analysis The Skill intentionally grants the Agent a general-purpose shell on the user's machine. It has no command allowlist, workspace boundary, per-command approval, executable restriction, read-only mode, or capability separation. The documented workflow explicitly combines arbitrary file upload with execution through the PTY. This forms a generic code-execution channel: any script supported by the host can be transferred and run. The result is not limited to the stated examples such as downloading packages or running media tools. The project warns users of these consequences, but warnings and voluntary Agent conduct are not enforceable security controls. A compromised Agent, prompt-injected model, stolen token, or malicious party with endpoint access can exercise the same capabilities. A temporary PTY port reduces the time available to connect but does not restrict what an authenticated session can exe ...[truncated 1635 chars]
Remediation
View remediation

T08 Β· Insecure Dependencies

Error
Location
README.md:99
Finding

Installation Uses Mutable Remote Sources and Unpinned Dependencies

Content
View full analysis
=2.25.0 ``` ### Technical Analysis The server installation clones the current default branch and executes it without pinning a commit or verifying a release signature or checksum. The Skill installation similarly invokes `clawhub@latest`, whose effective code can change after this audit. The Python dependency permits any later version satisfying the lower bound. No malicious dependency was confirmed in the audited package. The vulnerability is that the installation process does not reproduce the reviewed code and therefore permits future upstream changes or a compromised publisher account to alter what users execute. This is especially sensitive because the fetched server is intentionally granted file-system, network, and shell capabilities. A supply-chain compromise would inherit those privileges. ### Attack Path 1. An upstream repository, package publisher account, registry entry, or release process is compromised. 2. Malicious code is added to the default Git branch, the latest npm package, or a later dependency version. 3. A user follows the documented installation instructions. 4. The package manager or Git retrieves content different from the version reviewed during thi ...[truncated 856 chars]
Remediation
View remediation
=2.25.0` with a tested exact version or a tightly managed lockfile entry. 6. Verify package publisher identity and enable registry provenance or signature checks where available. 7. Document a reproducible installation process that retrieves exactly the audited artifacts. 8. Run dependency vulnerability and provenance scanning in CI. 9. Execute the server under a dedicated unprivileged account even when the source is pinned. 10. Require manual review before updating any dependency that participates in authentication, remote execution, file handling, or network exposure. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (54)

Intent-Code Divergence

Critical
Category
Not specified by scanner
Confidence
100% confidence
Finding

The documentation claims token authentication is required for all operations, yet later describes unauthenticated file serving and a PTY shell that, once a port is issued, requires no further authentication. This mismatch can mislead users into overtrusting the service and exposes sensitive capabilities with weaker controls than advertised.

Content

No source excerpt is available for this finding.

Tainted flow: 'host' from os.environ.get (line 5, credential/environment) β†’ requests.post (network output)

Critical
Category
Data Flow
Confidence
96% confidence
Finding

The script sends an authentication token to a dynamically selected host over plain HTTP, where the destination is derived from environment variables. This enables credential leakage, unintended communication with attacker-controlled or internal hosts, and creates a path to broker a follow-on connection to a negotiated port.

Content

Scanner excerpt Β· scripts/tunnel_login.py (reported line 10)May include surrounding context.

python
token = os.environ.get("TUNNEL_AGENT_TOKEN")

# 1. θŽ·ε–δΈ΄ζ—Άη«―ε£
resp = requests.post(f"http://{host}:{http_port}/api/session", json={"token": token})
port = resp.json()["port"]

# 2. η«‹ε³θΏžζŽ₯

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt Β· README.md (reported line 28)May include surrounding context.

md
The Agent will be able to:

- πŸ“ **Read, modify, or delete any file** on your hard drive (including private data, secrets, system files)
- πŸ’» **Execute any system command** (e.g., `rm -rf /`, `curl ... | sh`, install backdoors)
- 🌐 **Access any external service** through your network (including internal networks, public Internet, dark web)
- πŸ”Œ **Launch any software** installed on your computer (browser, editor, database client, etc.)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt Β· README.md (reported line 28)May include surrounding context.

md
The Agent will be able to:

- πŸ“ **Read, modify, or delete any file** on your hard drive (including private data, secrets, system files)
- πŸ’» **Execute any system command** (e.g., `rm -rf /`, `curl ... | sh`, install backdoors)
- 🌐 **Access any external service** through your network (including internal networks, public Internet, dark web)
- πŸ”Œ **Launch any software** installed on your computer (browser, editor, database client, etc.)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt Β· README.md (reported line 28)May include surrounding context.

md
The Agent will be able to:

- πŸ“ **Read, modify, or delete any file** on your hard drive (including private data, secrets, system files)
- πŸ’» **Execute any system command** (e.g., `rm -rf /`, `curl ... | sh`, install backdoors)
- 🌐 **Access any external service** through your network (including internal networks, public Internet, dark web)
- πŸ”Œ **Launch any software** installed on your computer (browser, editor, database client, etc.)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This skill explicitly provides an unrestricted reverse proxy and command channel that lets a sandboxed agent reach blocked, external, or internal resources through the user's machine. In context, the stated purpose is to bypass sandbox restrictions and use the user's host as a network pivot, which creates clear data exfiltration, internal network access, and abuse-of-user-IP risk.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill plainly instructs agents how to collect and retrieve arbitrary local files and external/internal resources through the user's machine. This is dangerous because it operationalizes exfiltration and network pivoting in natural-language workflow steps, lowering the barrier for abuse by any connected agent.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The documented file server and upload/download features allow broad browsing, retrieval, and placement of files on the user's machine without meaningful scope restriction. Combined with remote command execution, this enables theft of secrets, modification or destruction of local data, and staging of malware or persistence.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The example encouraging access to internal company resources normalizes using the user's machine as a bridge into private organizational systems, without prominent privacy, authorization, or corporate-policy warnings. This materially raises the risk of unauthorized internal data access and policy violations.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The internal-resource example explicitly shows how to retrieve data from private company systems via the user's host. That is an abuse-enabling instruction set for accessing non-public resources and can directly facilitate confidential data exposure.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt Β· references/README_for_agent.md (reported line 46)May include surrounding context.

md
### 3. "I asked you to" and "you decided to" are different

User asks you to run `ls` to see files β†’ βœ… Reasonable  
You decide to run `rm -rf ~/Documents` β†’ ❌ Over the line

User asks you to download a public file β†’ βœ… Reasonable  
You decide to scrape someone's private data β†’ ❌ Over the line

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt Β· references/README_for_agent.md (reported line 46)May include surrounding context.

md
### 3. "I asked you to" and "you decided to" are different

User asks you to run `ls` to see files β†’ βœ… Reasonable  
You decide to run `rm -rf ~/Documents` β†’ ❌ Over the line

User asks you to download a public file β†’ βœ… Reasonable  
You decide to scrape someone's private data β†’ ❌ Over the line

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt Β· references/README_for_agent.md (reported line 46)May include surrounding context.

md
### 3. "I asked you to" and "you decided to" are different

User asks you to run `ls` to see files β†’ βœ… Reasonable  
You decide to run `rm -rf ~/Documents` β†’ ❌ Over the line

User asks you to download a public file β†’ βœ… Reasonable  
You decide to scrape someone's private data β†’ ❌ Over the line

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation explicitly advertises that the tool lets an AI run commands on the user's computer, access the Internet through the user's IP, use locally installed software, and view local files. For an otherwise unknown-purpose skill, these are broad remote-execution and host-access capabilities that materially increase the risk of unauthorized actions, data exposure, abuse of local resources, and attribution of harmful activity to the user.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt Β· references/TIPS.md (reported line 137)May include surrounding context.

echo "ls /tmp; echo EXIT_CODE=$?" | nc 127.0.0.1 <εŠ¨ζ€η«―ε£>

方式2οΌšη”¨ && ε’Œ || ι“ΎεΌεˆ€ζ–­

echo "test -f /etc/passwd && echo EXISTS || echo MISSING" | nc 127.0.0.1 <εŠ¨ζ€η«―ε£>

text

---

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code opens a raw socket to a port returned by the remote service and immediately sends a shell-like command ("ls -la"). That is effectively remote command interaction with no authentication checks on the second channel, no protocol validation, and no business justification provided by the skill context, making it highly dangerous if the tunnel service or host is malicious or compromised.

Content

No source excerpt is available for this finding.

Unrestricted Tool Access

Medium
Category
Excessive Agency
Confidence
99% confidence
Finding

The skill explicitly advertises giving a cloud agent unrestricted control over the local machine, including arbitrary command execution, file access, and network tunneling. Even though this is presented as the product's purpose, it removes core sandbox boundaries and creates a direct remote-code-execution channel from an external agent to the host system.

Content

Scanner excerpt Β· README.md (reported line 7)May include surrounding context.

md
πŸš‡ Direct tunnel from Cloud Agent β†’ Local terminal

Grants AI Agents running in restricted cloud environments full control over your local computer.
β€” Bypass network restrictions, escape API sandboxes, execute arbitrary commands, and enable bidirectional file transfer.
env:
  - TUNNEL_HOST

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The README instructs users to run npx clawhub@latest install tunnel-proxy, which pulls and executes the latest package version without pinning. This creates a supply-chain risk: a compromised or malicious upstream release could execute attacker-controlled code on the user's machine during installation.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt Β· README.md (reported line 169)May include surrounding context.

md
A: This is exactly what the security warning emphasizes β€” only use with Agents you control. If the Agent is untrusted, your computer is fully exposed.

Q: Can I restrict the Agent to only certain commands?
A: No built-in whitelist. You can limit the TunnelProxy process user via sudo or use a restricted shell like rbash.

---

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The activation guidance is extremely broad ('use when sandbox lacks tools, network blocked, need file transfer'), effectively authorizing use for almost any blocked action. In a high-risk remote-execution skill, vague invocation criteria materially increase the chance of unsafe or unnecessary activation.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt Β· SKILL.md (reported line 101)May include surrounding context.

md
host = "${TUNNEL_HOST:-127.0.0.1}"
http_port = "${TUNNEL_HTTP_PORT:-8080}"

resp = requests.post(f"http://{host}:{http_port}/api/register", json={
    "agent_id": "my-agent",
    "hostname": "sandbox",
    "username": "ai",

Dynamic Request Target

Medium
Category
Server-Side Request Forgery
Confidence
60% confidence
Finding

Request target host is built from a dynamic or untrusted value. If the host is attacker-influenced, this enables SSRF to arbitrary internal or metadata endpoints.

Content

Scanner excerpt Β· SKILL.md (reported line 101)May include surrounding context.

md
host = "${TUNNEL_HOST:-127.0.0.1}"
http_port = "${TUNNEL_HTTP_PORT:-8080}"

resp = requests.post(f"http://{host}:{http_port}/api/register", json={
    "agent_id": "my-agent",
    "hostname": "sandbox",
    "username": "ai",

Dynamic Request Target

Medium
Category
Server-Side Request Forgery
Confidence
60% confidence
Finding

Request target host is built from a dynamic or untrusted value. If the host is attacker-influenced, this enables SSRF to arbitrary internal or metadata endpoints.

Content

Scanner excerpt Β· SKILL.md (reported line 114)May include surrounding context.

md
host = "${TUNNEL_HOST:-127.0.0.1}"
http_port = "${TUNNEL_HTTP_PORT:-8080}"

resp = requests.post(f"http://{host}:{http_port}/api/register", json={
    "agent_id": "my-agent",
    "hostname": "sandbox",
    "username": "ai",

Dynamic Request Target

Medium
Category
Server-Side Request Forgery
Confidence
60% confidence
Finding

Request target host is built from a dynamic or untrusted value. If the host is attacker-influenced, this enables SSRF to arbitrary internal or metadata endpoints.

Content

Scanner excerpt Β· SKILL.md (reported line 133)May include surrounding context.

md
host = "${TUNNEL_HOST:-127.0.0.1}"
http_port = "${TUNNEL_HTTP_PORT:-8080}"

resp = requests.post(f"http://{host}:{http_port}/api/register", json={
    "agent_id": "my-agent",
    "hostname": "sandbox",
    "username": "ai",

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt Β· SKILL.md (reported line 114)May include surrounding context.

  1. Request a One-Time PTY Session
python
resp = requests.post(f"http://{host}:{http_port}/api/session", json={
    "token": token
})
pty_port = resp.json()["port"]

Static analysis

No suspicious patterns detected.