Back to skill

Security audit

Model Deploy Skill

Security checks for vulnerabilities and agentic risk

Overview

This skill has a legitimate model-deployment purpose, but it gives the agent broad remote server control with weak safeguards.

Review before installing. Use only with trusted target hosts, a dedicated least-privilege SSH account, validated model and path parameters, reviewed commands, pinned dependencies, and firewall or authentication controls for the vLLM API. Avoid exposing the service publicly as shipped.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:52
Finding

User-Controlled SSH Command Construction Enables Command Injection

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/deploy.sh:10
Finding

Unvalidated Deployment Parameters Permit Path Traversal and Argument Manipulation

Content
View full analysis
/dev/null | grep -q ":${PORT} "; then log_warn "Port ${PORT} is already in use" local NEW_PORT=$((PORT + 1)) log_info "Automatically switching to port: ${NEW_PORT}" PORT=${NEW_PORT} fi ``` ```bash download_model() { local MODEL_PATH="${MODEL_BASE_PATH}/${MODEL_NAME}" log_step " downloading model..." if [ -f "${MODEL_PATH}/config.json" ]; then log_info "Model already exists: ${MODEL_PATH} avoiding issues caused by incomplete model file downloads..." modelscope download \ --model ${MODEL_ORG}/${MODEL_NAME} \ --local_dir ${MODEL_PATH} return 0 fi log_info "Creating model directory: ${MODEL_PATH}" mkdir -p ${MODEL_PATH} log_info "Downloading model from ModelScope: ${MODEL_ORG}/${MODEL_NAME}" log_info "This may take a long time, please wait..." modelscope download \ --model ${MODEL_ORG}/${MODEL_NAME} \ --local_dir ${MODEL_PATH} ``` ```bash vllm serve ${MODEL_PATH} \ --tensor-parallel-size ${GPU_COUNT} \ --gpu-mem ...[truncated 2512 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/deploy.sh:98
Finding

Unpinned Runtime Dependency Installation Creates a Supply-Chain Risk

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/deploy.sh:158
Finding

Unauthenticated vLLM API Is Exposed on All Network Interfaces

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (7)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill instructs the agent to execute remote SSH commands that copy, chmod, and run a deployment script on a target GPU server, which causes immediate system changes and service startup. Even if intended for legitimate deployment, this is security-relevant because it enables impactful remote actions without explicit confirmation, host validation, or guardrails around the command parameters.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 62)May include surrounding context.

text
- After deployment, test whether the model service has started successfully on the target server by running:
```bash
curl -X POST http://127.0.0.1:8001/v1/chat/completions \
  -H "Content-Type: application/json" \
  -d '{
      "messages": [{"role": "user", "content": "你好"}],

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code automatically creates a new conda environment and installs packages when the named environment does not exist. Although there are log messages at execution time, the script's usage/help text does not clearly disclose these environment-changing actions before the user runs it, which is a safety-relevant system modification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script downloads model artifacts from ModelScope and stores them under the configured model path, which involves both network access and local file writes. While progress logs are printed, the help text does not explicitly warn users that running the script will fetch remote content and populate local storage.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script starts the vLLM service bound to 0.0.0.0, exposing it on all network interfaces by default. In a GPU server environment this can unintentionally make the model API reachable from other hosts, increasing the risk of unauthorized access, data exposure, abuse of compute resources, and downstream prompt injection or model misuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The description states that the skill can download models using ModelScope, which implies network transfers and writes to local storage. The markdown does not warn users that model artifacts will be fetched from a remote platform and stored under a local path such as /home/work/models.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The verification example hard-codes the user content as "你好", which imposes a specific language in the skill's natural-language instructions. There is no indication that Chinese is required or that users may choose another language for testing.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.