Back to skill

Security audit

Ollama Ollama Herd

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent guide for using an Ollama fleet router, with disclosed but meaningful supply-chain, privacy, and host-change considerations.

Install only in an isolated environment or trusted fleet, avoid running it with elevated privileges, pin or review the ollama-herd package when possible, and confirm where prompts, audio, logs, and auto-pulled models will go before using it with sensitive data.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:16
Finding

Unpinned Third-Party Package Installation and Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 16–18
Vulnerability Type: Unpinned and unverifiable third-party dependency
Risk Level: Medium

Vulnerable Code

bash
pip install ollama-herd          # install the Ollama router
herd                             # start the Ollama router on port 11435
herd-node                        # run on each machine with Ollama installed

Technical Analysis

The setup instructions install the latest available ollama-herd release from PyPI without specifying an exact version or validating a cryptographic hash. They then direct the user to execute the package's installed herd and herd-node entry points.

Because the project contains only SKILL.md, the downloaded package implementation cannot be inspected as part of this audit. No lockfile, version constraint, integrity hash, vendored source, or reproducible-build provenance is provided. Consequently, the effective code executed by these commands may change after this Skill has been reviewed.

This does not establish that the current PyPI package is malicious. The weakness is that compromise of the package publisher, publishing infrastructure, or a future release could turn the documented installation process into a supply-chain execution path.

Attack Path

  1. An attacker compromises the package publisher account, release pipeline, or another component controlling the ollama-herd PyPI distribution.
  2. The attacker publishes a malicious release under the same package name.
  3. A user follows the Skill instructions and runs pip install ollama-herd.
  4. Because no version or hash is enforced, pip retrieves the attacker-controlled release.
  5. Installation hooks, imported package code, or the subsequently invoked herd and herd-node entry points execute the malicious payload.
  6. The payload operates with the privileges and environmental access of the user who performed the installation or ...[truncated 642 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the dependency to a specific, reviewed release, for example:
    bash
    python3 -m pip install "ollama-herd==<audited-version>"
    
  2. Distribute a locked requirements file containing cryptographic hashes and install it with hash enforcement:
    bash
    python3 -m pip install --require-hashes -r requirements.txt
    
  3. Verify release provenance, package signatures, source tags, and build artifacts before recommending a version.
  4. Include the relevant source code in the audited project or link the Skill to an immutable commit rather than only to a mutable package release.
  5. Install and execute the package in an isolated virtual environment or container under a dedicated, non-privileged account.
  6. Avoid running pip, herd, or herd-node with administrator or root privileges.
  7. Review installation hooks and both entry points before deployment, and restrict their filesystem and network access to the minimum required for fleet routing.
  8. Establish a controlled update process so newer package releases require renewed review and integrity verification rather than being installed automatically.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 47)May include surrounding context.

bash
# Ollama chat — routed through the Ollama fleet
curl http://localhost:11435/api/chat -d '{
  "model": "qwen3:235b",
  "messages": [{"role": "user", "content": "Hello via Ollama Herd"}],
  "stream": false

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly advertises 'Ollama Auto-pull' that downloads missing models automatically, which can trigger large network transfers, disk consumption, and changes to the host fleet without clear warning or consent at the point of use. In a self-hosted multi-node routing context, this can unexpectedly alter multiple machines and surprise users who assumed inference-only behavior.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 113)May include surrounding context.

Ollama Image generation

bash
curl -o image.png http://localhost:11435/api/generate-image \
  -H "Content-Type: application/json" \
  -d '{"model":"z-image-turbo","prompt":"a sunset via Ollama Herd","width":1024,"height":1024,"steps":4}'

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The speech-to-text example encourages uploading a local audio file to the routing service but does not warn that sensitive voice content may be transmitted across the local fleet and potentially logged or retained. Even on localhost, the request is forwarded to another machine, so the privacy boundary is broader than the example implies.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.