T09 · Insecure Skill Coding Practices
- Location
SKILL.md:52- Finding
User-Controlled SSH Command Construction Enables Command Injection
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill has a legitimate model-deployment purpose, but it gives the agent broad remote server control with weak safeguards.
Review before installing. Use only with trusted target hosts, a dedicated least-privilege SSH account, validated model and path parameters, reviewed commands, pinned dependencies, and firewall or authentication controls for the vLLM API. Avoid exposing the service publicly as shipped.
SKILL.md:52User-Controlled SSH Command Construction Enables Command Injection
scripts/deploy.sh:10Unvalidated Deployment Parameters Permit Path Traversal and Argument Manipulation
scripts/deploy.sh:98Unpinned Runtime Dependency Installation Creates a Supply-Chain Risk
scripts/deploy.sh:158Unauthenticated vLLM API Is Exposed on All Network Interfaces
The skill instructs the agent to execute remote SSH commands that copy, chmod, and run a deployment script on a target GPU server, which causes immediate system changes and service startup. Even if intended for legitimate deployment, this is security-relevant because it enables impactful remote actions without explicit confirmation, host validation, or guardrails around the command parameters.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
- After deployment, test whether the model service has started successfully on the target server by running:
```bash
curl -X POST http://127.0.0.1:8001/v1/chat/completions \
-H "Content-Type: application/json" \
-d '{
"messages": [{"role": "user", "content": "你好"}],
This code automatically creates a new conda environment and installs packages when the named environment does not exist. Although there are log messages at execution time, the script's usage/help text does not clearly disclose these environment-changing actions before the user runs it, which is a safety-relevant system modification.
The script downloads model artifacts from ModelScope and stores them under the configured model path, which involves both network access and local file writes. While progress logs are printed, the help text does not explicitly warn users that running the script will fetch remote content and populate local storage.
The script starts the vLLM service bound to 0.0.0.0, exposing it on all network interfaces by default. In a GPU server environment this can unintentionally make the model API reachable from other hosts, increasing the risk of unauthorized access, data exposure, abuse of compute resources, and downstream prompt injection or model misuse.
The description states that the skill can download models using ModelScope, which implies network transfers and writes to local storage. The markdown does not warn users that model artifacts will be fetched from a remote platform and stored under a local path such as /home/work/models.
The verification example hard-codes the user content as "你好", which imposes a specific language in the skill's natural-language instructions. There is no indication that Chinese is required or that users may choose another language for testing.
No suspicious patterns detected.