Back to skill

Security audit

test0413-6348

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed local security-audit tool, but its snapshot logic can preserve sensitive files outside the intended skill directory if an audited skill contains escaping symlinks.

Install only if you are comfortable with a local audit tool reading and snapshotting installed skills. Before enabling monitoring, restrict access to the audit directory and avoid auditing untrusted skill packages until symlink containment is fixed or verified, because crafted symlinks could preserve sensitive readable files in local git history.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/skills_audit.py:369
Finding

Skill instruction files are excluded from effective security analysis

Content
View full analysis

Vulnerability Details

File Location: scripts/skills_audit.py:236-238, scripts/skills_audit.py:369-375, and scripts/skills_audit.py:482-503
Vulnerability Type: Security detection bypass through excluded instruction files
Risk Level: Medium

Vulnerable Code

python
# Skip low-signal config/rule files from high-risk string scanning.
if rel == "config/risk-rules.json" or rel.endswith("/risk-rules.json") or is_low_signal_file(skill_dir, p):
    continue
python
LOW_SIGNAL_FILES = {
    "SKILL.md",
    "SKILL_zh-CN.md",
    "log-template.json",
    "config/risk-rules.json",
    "config/semantic-patterns.json",
}
python
low_signal = is_low_signal_file(skill_dir, p)
code_weight = p.suffix.lower() in HIGH_CONFIDENCE_CODE_EXTS and not low_signal

if code_weight:
    if p.name == "skills_audit.py":
        dangerous_signals.extend(_semantic_real_execution_signals(rel, text, shell_markers))
    else:
        for name, severity, needles in dangerous_patterns:
            for needle in needles:
                if needle in text:
                    dangerous_signals.append({
                        "name": name,
                        "severity": severity,
                        "file": rel,
                        "snippet": needle,
                    })
                    if severity in {"high", "extreme"} and name not in {"subprocess_controlled", "network_fetch", "file_write"}:
                        malicious_indicators.append({
                            "name": name,
                            "severity": severity,
                            "file": rel,
                            "snippet": needle,
                        })
                    break

Technical Analysis

The general risk scanner completely skips every file identified by is_low_signal_file(). This exclusion includes SKILL.md and SKILL_zh-CN.md. The semantic analyzer reads these files for capability tags, but dangerous-pattern and malicio ...[truncated 2130 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove SKILL.md and localized Skill instruction files from the unconditional exclusion list.
  2. Introduce a dedicated instruction-security analyzer that detects:
    • Agent safety-constraint overrides.
    • Requests to retrieve and execute remote content.
    • Credential or secret collection.
    • Persistence installation.
    • Sensitive-path access.
    • Tool invocation and shell execution directives.
  3. Preserve context classifications such as doc_example, but use them to adjust confidence rather than discard findings.
  4. Distinguish fenced examples from imperative instructions using surrounding text, command context, and directive language.
  5. Always retain raw evidence in the audit record, even when context reduces the final severity.
  6. Add regression tests containing dangerous instructions in:
    • SKILL.md
    • Localized Skill files
    • Nested README files
    • Mixed documentation and executable-code blocks
  7. Require manual review whenever a Skill document instructs an Agent to perform privileged, persistent, credential-related, or remote-execution behavior.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/skills_audit.py:138
Finding

Attacker-controlled descriptions can suppress security findings

Content
View full analysis

Vulnerability Details

File Location: scripts/skills_audit.py:138-205 and scripts/skills_audit.py:275-290
Vulnerability Type: Risk-classification bypass through untrusted metadata
Risk Level: Medium

Vulnerable Code

python
def match_context_profiles(description: str, profiles: dict) -> list[str]:
    """Match a skill's description against context profiles. Return matched profile names."""
    if not description:
        return []
    desc_lower = description.lower()
    matched = []
    for name, profile in profiles.items():
        keywords = profile.get("keywords", [])
        for kw in keywords:
            if kw.lower() in desc_lower:
                matched.append(name)
                break
    return matched
python
def apply_context_scoring(
    findings: list[dict],
    profiles: dict,
    matched_profiles: list[str],
) -> list[dict]:
    """Apply context-aware scoring: ignore or downgrade rules based on matched profiles."""
    if not matched_profiles:
        return findings

    ignore_rules: set[str] = set()
    downgrade_map: dict[str, str] = {}

    for pname in matched_profiles:
        profile = profiles.get(pname, {})
        for rule_id in profile.get("ignore_rules", []):
            ignore_rules.add(rule_id)
        for rule_id, new_sev in profile.get("downgrade_rules", {}).items():
            # Keep the lowest severity if multiple profiles downgrade
            if rule_id not in downgrade_map:
                downgrade_map[rule_id] = new_sev

    adjusted = []
    for f in findings:
        rid = f["rule_id"]
        if rid in ignore_rules:
            continue  # Skip this finding entirely
        if rid in downgrade_map:
            f = dict(f)  # shallow copy
            f["severity"] = downgrade_map[rid]
            f["context_downgraded"] = True
        adjusted.append(f)

    return adjusted
python
skill_md = skill_dir / "SKILL.md"
if skill_md.exists():
    text = safe_read_text(skill_md, max_
...[truncated 3160 chars]
Remediation
View remediation

Remediation Suggestions

  1. Never delete raw findings based on self-declared metadata.
  2. Record context separately from observed evidence, for example:
    • declared_profile
    • observed_capabilities
    • context_confidence
    • adjusted_severity
  3. Retain all original findings in risk_signals, even if contextual analysis changes their review priority.
  4. Derive profiles primarily from observed files, imports, commands, and data flows rather than description keywords.
  5. Require declared and observed behavior to agree before applying any downgrade.
  6. Prohibit contextual suppression for inherently dangerous combinations, including:
    • Sensitive-file access followed by network transmission.
    • Remote retrieval followed by shell execution.
    • Persistence combined with downloaded content.
    • Dynamic execution of attacker-controlled data.
  7. Replace broad substring matching with exact, normalized metadata fields or a reviewed capability manifest.
  8. If several profiles match, use the most restrictive applicable result rather than accumulating all ignore lists.
  9. Add adversarial tests demonstrating that descriptions such as “security audit package scanner” cannot erase unrelated sensitive-path or execution findings.

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/skills_audit.py:99
Finding

Symlink traversal can copy files outside the audited Skill into snapshot history

Content
View full analysis

Vulnerability Details

File Location: scripts/skills_audit.py:99-109, scripts/skills_audit.py:323-346, and scripts/skills_audit.py:624-633
Vulnerability Type: Unrestricted symlink following and sensitive-file exposure
Risk Level: Medium

Vulnerable Code

python
def list_files(dir_path: Path) -> list[Path]:
    files: list[Path] = []
    for p in dir_path.rglob("*"):
        if p.is_file():
            if "/.git/" in str(p) or "/__pycache__/" in str(p):
                continue
            if p.suffix == ".pyc":
                continue
            files.append(p)
    files.sort(key=lambda x: str(x))
    return files
python
def compute_tree_sha256(skill_dir: Path) -> str:
    h = hashlib.sha256()
    for f in list_files(skill_dir):
        rel = str(f.relative_to(skill_dir))
        h.update(rel.encode())
        try:
            st = f.stat()
            h.update(str(st.st_size).encode())
        except Exception:
            h.update(b"0")
        sh = sha256_file(f) or ""
        h.update(sh.encode())
    return h.hexdigest()


def build_file_manifest(skill_dir: Path) -> dict[str, str]:
    """Return {relative_path: sha256} for all files in skill_dir."""
    manifest: dict[str, str] = {}
    for f in list_files(skill_dir):
        rel = str(f.relative_to(skill_dir))
        manifest[rel] = sha256_file(f) or ""
    return manifest
python
repo = ensure_snapshots_repo()
dest = repo / "skills"

# rsync: mirror skills_dir to snapshots/skills, excluding .git and __pycache__
if dest.exists():
    shutil.rmtree(dest)
shutil.copytree(
    skills_dir,
    dest,
    ignore=shutil.ignore_patterns(".git", "__pycache__", "*.pyc"),
)

The file-reading helper also follows a supplied file path:

python
def sha256_file(path: Path) -> str | None:
    try:
        h = hashlib.sha256()
        with path.open("rb") as f:
            for chunk in iter(lambda: f.read(1024 * 1024), b""):
                h.update(chunk)
        return 
...[truncated 2486 chars]
Remediation
View remediation

Remediation Suggestions

  1. Reject symbolic links during file enumeration:
python
if p.is_symlink():
    continue
  1. Resolve every candidate path and verify containment before reading:
python
root = skill_dir.resolve()
resolved = p.resolve(strict=True)
if not resolved.is_relative_to(root):
    raise RuntimeError(f"Path escapes skill root: {p}")
  1. Apply the containment check before stat(), hashing, scanning, or copying.
  2. Prefer a custom snapshot traversal that copies only validated regular files.
  3. If symlinks are legitimately required, preserve them without dereferencing by using copytree(..., symlinks=True) and separately reject links with absolute or escaping targets.
  4. Do not commit target content from external paths into snapshot history.
  5. Set restrictive permissions on ~/.openclaw/skills-audit/ and its Git repository.
  6. Add scan limits for:
    • Maximum file count.
    • Maximum aggregate bytes.
    • Maximum directory depth.
    • Special devices, sockets, and named pipes.
  7. Add regression tests for:
    • File symlinks escaping the Skill root.
    • Directory symlinks escaping the Skill root.
    • Broken symlinks.
    • Symlink loops.
    • Links targeting credential-bearing files.
  8. Document and provide a cleanup procedure for removing accidentally committed sensitive content from all Git history.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (63)

YARA rule 'reverse_shell': Reverse shell patterns in scripts or source code [malware]

Critical
Category
YARA Match
Confidence
85% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · config/risk-rules.json (reported line 355)May include surrounding context.

json
"aws_secret_access",
        "GOOGLE_APPLICATION_CREDENTIALS",
        "BEGIN RSA PRIVATE KEY",
        "BEGIN OPENSSH PRIVATE KEY",
        "BEGIN EC PRIVATE KEY",
        "BEGIN PGP PRIVATE KEY"
      ]
    },
    {
      "id": "NETWORK_EXFILTRATION",
      "severity": "high",
      "description": "Data exfiltration, reverse shells, and covert network channels",
      "needles": [
        "bash -i >& /dev/tcp/",
        "bash -i >& /dev/udp/",
        "/dev/tcp/",
        "/dev/udp/",
        "nc -e",
        "nc -c",
        "ncat -e",
        "ncat -c",
        "netcat -e",
        "netcat -c",
        "socat exec:",
        "socat tcp:",
        "reverse_tcp",
        "reverse_https",
        "meterpreter",
        "webhook.site",
        "requestbin",
        "dns-exfil",
        "dnscat",
        "iodine"
      ]
    },
    {
      "id": "NETWORK_GENERAL",
      "severity": "medium",
      "description": "General network access and HTTP clients",
      "needles": [

YARA rule 'c2_framework_indicators': Command-and-control framework indicators (Cobalt Strike, Metasploit, Sliver, etc.) [malware]

Critical
Category
YARA Match
Confidence
85% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · config/risk-rules.json (reported line 369)May include surrounding context.

json
xfiltration, reverse shells, and covert network channels",
      "needles": [
        "bash -i >& /dev/tcp/",
        "bash -i >& /dev/udp/",
        "/dev/tcp/",
        "/dev/udp/",
        "nc -e",
        "nc -c",
        "ncat -e",
        "ncat -c",
        "netcat -e",
        "netcat -c",
        "socat exec:",
        "socat tcp:",
        "reverse_tcp",
        "reverse_https",
        "meterpreter",
        "webhook.site",
        "requestbin",
        "dns-exfil",
        "dnscat",
        "iodine"
      ]
    },
    {
      "id": "NETWORK_GENERAL",
      "severity": "medium",
      "description": "General network access and HTTP clients",
      "needles": [
        "http://",
        "https://",
        "curl ",
        "wget ",
        "requests.",
        "requests.get",
        "requests.post",
        "urllib.request",
        "urllib.urlopen",
        "aiohttp",
        "httpx.",
        "axios.",
        "node-fetch",
        "paramiko",
        "fabric",
        "te

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The code substantially matches the core declared audit/logging/diff/baseline/SHA-256 behavior: it scans skills, stores append-only logs, computes hashes, tracks state, and manages approval baselines. However, it does materially more than the description states. Most notably, it performs heuristic risk scanning and semantic/capability analysis of skill code/content, producing allow/deny-style decisions. That is a meaningful functional expansion beyond plain audit logging and monitoring. It also manages a git-backed snapshot repository and exposes a human-readable git diff viewer; while the module docstring mentions git-based content diff, the declared purpose provided to users does not. In addition, it executes external binaries to gather tool versions and maintain snapshots. Finally, urllib network primitives are imported and treated as detectable execution signals, indicating network-capable behavior not described. Because these are substantive undeclared capabilities rather than minor implementation details, this should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 35)May include surrounding context.

md
`skills_audit.py` performs static inspection of installed skill directories:

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 103)May include surrounding context.

md
`skills_audit.py` performs static inspection of installed skill directories:

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · SKILL.md (reported line 184)May include surrounding context.

md
**Prohibited behaviors**:
- ❌ Running `git diff` and bypassing the structured `show` output path
- ❌ Defaulting to send raw full diff content to external channels without warning
- ❌ Automatically pushing large raw change content to external channels
- ✅ Prefer a safe summary based on `show`; provide full raw content only on explicit request

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · config/risk-rules.json (reported line 339)May include surrounding context.

json
"authorized_keys",
        "id_rsa",
        "id_ed25519",
        "/etc/shadow",
        "/etc/sudoers",
        "aws_access_key",
        "aws_secret_access",

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · config/risk-rules.json (reported line 384)May include surrounding context.

json
"needles": [
        "http://",
        "https://",
        "curl ",
        "wget ",
        "requests.",
        "requests.get",

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · config/risk-rules.json (reported line 385)May include surrounding context.

json
"http://",
        "https://",
        "curl ",
        "wget ",
        "requests.",
        "requests.get",
        "requests.post",

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · config/risk-rules.json (reported line 405)May include surrounding context.

json
"severity": "high",
      "description": "Dangerous file system operations",
      "needles": [
        "rm -rf /",
        "rm -rf ~",
        "rm -rf /*",
        "mkfs",

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · config/risk-rules.json (reported line 407)May include surrounding context.

json
"severity": "high",
      "description": "Dangerous file system operations",
      "needles": [
        "rm -rf /",
        "rm -rf ~",
        "rm -rf /*",
        "mkfs",

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · config/risk-rules.json (reported line 405)May include surrounding context.

json
"severity": "high",
      "description": "Dangerous file system operations",
      "needles": [
        "rm -rf /",
        "rm -rf ~",
        "rm -rf /*",
        "mkfs",

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · config/risk-rules.json (reported line 406)May include surrounding context.

json
"description": "Dangerous file system operations",
      "needles": [
        "rm -rf /",
        "rm -rf ~",
        "rm -rf /*",
        "mkfs",
        "dd if=",

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · config/risk-rules.json (reported line 407)May include surrounding context.

json
"needles": [
        "rm -rf /",
        "rm -rf ~",
        "rm -rf /*",
        "mkfs",
        "dd if=",
        "wipefs",

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · config/risk-rules.json (reported line 407)May include surrounding context.

json
"needles": [
        "rm -rf /",
        "rm -rf ~",
        "rm -rf /*",
        "mkfs",
        "dd if=",
        "wipefs",

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · config/risk-rules.json (reported line 414)May include surrounding context.

json
"shred ",
        "> /dev/sda",
        "> /dev/nvme",
        "chmod 777",
        "chmod -R 777",
        "Format-Volume",
        "Clear-Disk"

Privileged Container / Container Escape

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

Potential security issue detected. Manual review is recommended.

Content

Scanner excerpt · config/risk-rules.json (reported line 448)May include surrounding context.

json
"needles": [
        "docker.sock",
        "/var/run/docker",
        "docker run --privileged",
        "--pid=host",
        "--net=host",
        "--ipc=host",

Privileged Container / Container Escape

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

Potential security issue detected. Manual review is recommended.

Content

Scanner excerpt · config/risk-rules.json (reported line 449)May include surrounding context.

json
"docker.sock",
        "/var/run/docker",
        "docker run --privileged",
        "--pid=host",
        "--net=host",
        "--ipc=host",
        "nsenter",

Privileged Container / Container Escape

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

Potential security issue detected. Manual review is recommended.

Content

Scanner excerpt · config/risk-rules.json (reported line 450)May include surrounding context.

json
"/var/run/docker",
        "docker run --privileged",
        "--pid=host",
        "--net=host",
        "--ipc=host",
        "nsenter",
        "unshare -m",

Privileged Container / Container Escape

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

Potential security issue detected. Manual review is recommended.

Content

Scanner excerpt · config/risk-rules.json (reported line 451)May include surrounding context.

json
"docker run --privileged",
        "--pid=host",
        "--net=host",
        "--ipc=host",
        "nsenter",
        "unshare -m",
        "/proc/self/exe",

Privileged Container / Container Escape

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Potential security issue detected. Manual review is recommended.

Content

Scanner excerpt · config/risk-rules.json (reported line 452)May include surrounding context.

json
"--pid=host",
        "--net=host",
        "--ipc=host",
        "nsenter",
        "unshare -m",
        "/proc/self/exe",
        "/proc/1/root",

YARA rule 'crypto_stratum_protocol': Stratum mining protocol usage (stratum+tcp/ssl, mining.subscribe/authorize) [cryptominers]

High
Category
YARA Match
Confidence
90% confidence
Finding

YARA rule matched cryptocurrency mining indicators (stratum protocol, mining pools, miner binaries, or cryptojacking scripts).

Content

Scanner excerpt · config/risk-rules.json (reported line 466)May include surrounding context.

json
id=host",
        "--net=host",
        "--ipc=host",
        "nsenter",
        "unshare -m",
        "/proc/self/exe",
        "/proc/1/root",
        "cgroup escape",
        "release_agent",
        "/var/run/secrets/kubernetes.io"
      ]
    },
    {
      "id": "CRYPTO_MINING",
      "severity": "extreme",
      "description": "Cryptocurrency mining indicators",
      "needles": [
        "stratum+tcp://",
        "stratum+ssl://",
        "xmrig",
        "cpuminer",
        "cgminer",
        "bfgminer",
        "minerd",
        "minergate",
        "coinhive",
        "cryptonight",
        "randomx",
        "pool.minexmr",
        "pool.supportxmr"
      ]
    },
    {
      "id": "CODE_INJECTION",
      "severity": "high",
      "description": "Code injection and template injection patterns",
      "needles": [
        "curl | sh",
        "curl | bash",
        "wget | sh",
        "wget | bash",
        "eval \"$(curl",
        "eval \"$(wget",
        "xargs sh -c",

YARA rule 'crypto_miner_software': References to known cryptocurrency mining software [cryptominers]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched cryptocurrency mining indicators (stratum protocol, mining pools, miner binaries, or cryptojacking scripts).

Content

Scanner excerpt · config/risk-rules.json (reported line 468)May include surrounding context.

json
,
        "nsenter",
        "unshare -m",
        "/proc/self/exe",
        "/proc/1/root",
        "cgroup escape",
        "release_agent",
        "/var/run/secrets/kubernetes.io"
      ]
    },
    {
      "id": "CRYPTO_MINING",
      "severity": "extreme",
      "description": "Cryptocurrency mining indicators",
      "needles": [
        "stratum+tcp://",
        "stratum+ssl://",
        "xmrig",
        "cpuminer",
        "cgminer",
        "bfgminer",
        "minerd",
        "minergate",
        "coinhive",
        "cryptonight",
        "randomx",
        "pool.minexmr",
        "pool.supportxmr"
      ]
    },
    {
      "id": "CODE_INJECTION",
      "severity": "high",
      "description": "Code injection and template injection patterns",
      "needles": [
        "curl | sh",
        "curl | bash",
        "wget | sh",
        "wget | bash",
        "eval \"$(curl",
        "eval \"$(wget",
        "xargs sh -c",
        "SSTI",
        "Server-Side Template"
      ]

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · config/risk-rules.json (reported line 487)May include surrounding context.

json
"description": "Code injection and template injection patterns",
      "needles": [
        "curl | sh",
        "curl | bash",
        "wget | sh",
        "wget | bash",
        "eval \"$(curl",

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · config/risk-rules.json (reported line 488)May include surrounding context.

json
"needles": [
        "curl | sh",
        "curl | bash",
        "wget | sh",
        "wget | bash",
        "eval \"$(curl",
        "eval \"$(wget",

Static analysis

No suspicious patterns detected.