Back to skill

Security audit

GemmaMatch — Gemma 4 Local Hardware Matcher

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly coherent, but it tells users to run a terminal command generated by a mutable external website without showing or constraining that command in the reviewed artifact.

Review any command from the GemmaMatch website before running it. Prefer simple, recognizable Ollama or LM Studio commands, avoid commands that pipe remote content into a shell or request administrator privileges, and do not run it if it includes unrelated file, credential, network, or system-modification actions.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Warning
Location
SKILL.md:45
Finding

Externally Controlled Terminal Command Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 45-48
Vulnerability Type: T03: Remote Payload Retrieval and Execution
Risk Level: Medium

Vulnerable Content:

markdown
1. Visit https://www.gemmamatch.com
2. Allow hardware detection (or enter specs manually)
3. Get your recommended model + run command
4. Copy the command and run it in your terminal

Technical Analysis

The skill directs users to obtain a terminal command from a mutable external website and execute it locally. The project does not define, validate, constrain, or pin the command that the website may return. Consequently, the effective command can change after this skill has been reviewed.

This creates a remote payload execution risk: if the external website, its hosting infrastructure, or its content-delivery path is compromised, an attacker could replace the expected model command with arbitrary shell instructions. Successful exploitation still requires the user to copy and execute the supplied command.

Attack Path

  1. An attacker compromises or otherwise gains control of https://www.gemmamatch.com or its command-generation functionality.
  2. The attacker changes the generated recommendation command to include a malicious payload.
  3. A user follows the instructions in SKILL.md and visits the website.
  4. The website presents the attacker-controlled command as a legitimate model deployment command.
  5. The user copies and executes the command in a terminal.
  6. The payload runs with the permissions of that user.

Impact Assessment

A successful payload could execute arbitrary commands with the invoking user's privileges. Depending on those privileges and the generated command, this may permit installation of unwanted software, modification or deletion of user-accessible files, theft of accessible credentials or other local data, and further payload retrieval.

The reviewed project contains only SKILL.md ...[truncated 230 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace externally generated terminal instructions with fixed, reviewable command templates included directly in the skill.
  • Strictly allowlist executable names, subcommands, flags, and argument formats if commands must be generated dynamically.
  • Present commands as untrusted suggestions and require users to inspect them before execution.
  • Never recommend piping downloaded content directly into a shell.
  • Pin all referenced packages, models, and downloadable artifacts to trusted sources and verified versions.
  • Publish cryptographic checksums or signatures for downloaded artifacts and instruct users to verify them before use.
  • Avoid requesting elevated privileges; clearly warn users if a command requires administrator or root access.
  • Make the website's command-generation source available for review and apply deployment integrity controls, restrictive content security policies, and strong administrative authentication.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.