T09 · Insecure Skill Coding Practices
- Location
SKILL.md:37- Finding
Predictable Hardcoded Password for a Sudo-Capable Account
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This VPS maintenance skill is broadly aligned with server administration, but its copy-paste commands can lock users out, create a known sudo password, replace package sources, and delete important system state without enough safeguards.
Review carefully before installing or using this skill. Do not copy its account, SSH, firewall, APT, or cleanup commands directly on a production VPS. Replace the hardcoded password workflow with interactive or key-only setup, target the intended user's authorized_keys explicitly, test SSH in a second session before disabling password login or enabling a drop firewall, prefer HTTPS and distribution-matched package sources, and avoid broad unattended deletion of logs, temp directories, caches, packages, or kernels.
SKILL.md:37Predictable Hardcoded Password for a Sudo-Capable Account
SKILL.md:42Destructive SSH Key Replacement Can Configure the Wrong Account and Cause Remote Lockout
SKILL.md:16System Package Sources Are Replaced with Plaintext HTTP Mirrors
SKILL.md:170Indiscriminate Non-Interactive Cleanup Can Delete Active State and Forensic Records
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
mkdir -p ~/.ssh chmod 700 ~/.ssh echo "你的公钥" > ~/.ssh/authorized_keys chmod 600 ~/.ssh/authorized_keys
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
mkdir -p ~/.ssh chmod 700 ~/.ssh echo "你的公钥" > ~/.ssh/authorized_keys chmod 600 ~/.ssh/authorized_keys
YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).
CODENAME}-updates main contrib non-free non-free-firmware EOF
apt update
### 2. 账户安全
```bash
# 创建普通用户(禁止直接用 root)
useradd -m -s /bin/bash username
echo "username:StrongPassword123!" | chpasswd
usermod -aG sudo username
# 配置 SSH 密钥
mkdir -p ~/.ssh
chmod 700 ~/.ssh
echo "你的公钥" > ~/.ssh/authorized_keys
chmod 600 ~/.ssh/authorized_keys
# 备份配置
cp /etc/ssh/sshd_config /etc/ssh/sshd_config.backup
# 修改默认端口(防扫描)
sed -i 's/^#*Port .*/Port 54321/' /etc/ssh/sshd_config
# 加固配置
cat >> /etc/ssh/sshd_config <<EOF
PasswordAuthentication no
PermitRootLogin prohibit-password
PubkeyAuthentication yes
LoginGraceTime 30
MaxAuthTries 3
EOF
systemctl restart ssh
# 安装 nftables(替代 ufw)
apt-get install -y nftables
# 配置规则(只开放 SSH�
The SSH hardening and firewall steps change the SSH port, disable password authentication, and apply a default-drop firewall policy with only the new SSH port allowed, but they do not require validation before restart or enablement. If the key is not installed correctly, the port is wrong, or the cloud provider firewall does not match, the user can be locked out of the server entirely.
The exact command rm -rf /tmp/* 2>/dev/null suppresses errors while recursively deleting all visible contents of /tmp, which reduces operator visibility into what failed or was removed. Error suppression combined with forceful deletion makes accidental impact harder to detect and recover from.
find /var/log -type f -name "*.old" -delete 2>/dev/null
# 4. 清理临时文件
rm -rf /tmp/* 2>/dev/null
rm -rf /var/tmp/* 2>/dev/null
# 5. 清理用户缓存
The exact command rm -rf /tmp/* 2>/dev/null suppresses errors while recursively deleting all visible contents of /tmp, which reduces operator visibility into what failed or was removed. Error suppression combined with forceful deletion makes accidental impact harder to detect and recover from.
find /var/log -type f -name "*.old" -delete 2>/dev/null
# 4. 清理临时文件
rm -rf /tmp/* 2>/dev/null
rm -rf /var/tmp/* 2>/dev/null
# 5. 清理用户缓存
The exact command rm -rf /tmp/* 2>/dev/null suppresses errors while recursively deleting all visible contents of /tmp, which reduces operator visibility into what failed or was removed. Error suppression combined with forceful deletion makes accidental impact harder to detect and recover from.
find /var/log -type f -name "*.old" -delete 2>/dev/null
# 4. 清理临时文件
rm -rf /tmp/* 2>/dev/null
rm -rf /var/tmp/* 2>/dev/null
# 5. 清理用户缓存
rm -rf /var/tmp/* 2>/dev/null combines broad deletion with hidden errors, making unsafe cleanup less observable. On production VPS systems, this can mask permission issues or partial deletion states while still damaging application workflows.
# 4. 清理临时文件
rm -rf /tmp/* 2>/dev/null
rm -rf /var/tmp/* 2>/dev/null
# 5. 清理用户缓存
rm -rf ~/.cache/* 2>/dev/null
rm -rf /var/tmp/* 2>/dev/null combines broad deletion with hidden errors, making unsafe cleanup less observable. On production VPS systems, this can mask permission issues or partial deletion states while still damaging application workflows.
# 4. 清理临时文件
rm -rf /tmp/* 2>/dev/null
rm -rf /var/tmp/* 2>/dev/null
# 5. 清理用户缓存
rm -rf ~/.cache/* 2>/dev/null
rm -rf /var/tmp/* 2>/dev/null combines broad deletion with hidden errors, making unsafe cleanup less observable. On production VPS systems, this can mask permission issues or partial deletion states while still damaging application workflows.
# 4. 清理临时文件
rm -rf /tmp/* 2>/dev/null
rm -rf /var/tmp/* 2>/dev/null
# 5. 清理用户缓存
rm -rf ~/.cache/* 2>/dev/null
rm -rf ~/.cache/* 2>/dev/null silently removes all cache contents for the current user while hiding failures, which can obscure troubleshooting and unexpectedly reset tool state. The danger is moderate to low, but it is still an unsafe blanket operation in generic guidance.
rm -rf /var/tmp/* 2>/dev/null
rm -rf ~/.cache/* 2>/dev/null
---
rm -rf ~/.cache/* 2>/dev/null silently removes all cache contents for the current user while hiding failures, which can obscure troubleshooting and unexpectedly reset tool state. The danger is moderate to low, but it is still an unsafe blanket operation in generic guidance.
rm -rf /var/tmp/* 2>/dev/null
rm -rf ~/.cache/* 2>/dev/null
---
rm -rf ~/.cache/* 2>/dev/null silently removes all cache contents for the current user while hiding failures, which can obscure troubleshooting and unexpectedly reset tool state. The danger is moderate to low, but it is still an unsafe blanket operation in generic guidance.
rm -rf /var/tmp/* 2>/dev/null
rm -rf ~/.cache/* 2>/dev/null
---
Including rm -rf /tmp/* 2>/dev/null inside a scheduled cleanup script creates a recurring destructive action with suppressed errors, increasing the chance of unnoticed service impact. This is especially risky on multi-service VPS hosts where /tmp is actively used.
find /var/log -type f -name "*.log" -mtime +7 -delete 2>/dev/null
# 清理临时文件
rm -rf /tmp/* 2>/dev/null
rm -rf /var/tmp/* 2>/dev/null
echo "=== 清理完成 ==="
Including rm -rf /tmp/* 2>/dev/null inside a scheduled cleanup script creates a recurring destructive action with suppressed errors, increasing the chance of unnoticed service impact. This is especially risky on multi-service VPS hosts where /tmp is actively used.
find /var/log -type f -name "*.log" -mtime +7 -delete 2>/dev/null
# 清理临时文件
rm -rf /tmp/* 2>/dev/null
rm -rf /var/tmp/* 2>/dev/null
echo "=== 清理完成 ==="
Including rm -rf /tmp/* 2>/dev/null inside a scheduled cleanup script creates a recurring destructive action with suppressed errors, increasing the chance of unnoticed service impact. This is especially risky on multi-service VPS hosts where /tmp is actively used.
find /var/log -type f -name "*.log" -mtime +7 -delete 2>/dev/null
# 清理临时文件
rm -rf /tmp/* 2>/dev/null
rm -rf /var/tmp/* 2>/dev/null
echo "=== 清理完成 ==="
Automated rm -rf /var/tmp/* 2>/dev/null is dangerous because it recursively deletes potentially important temporary data and conceals failures. In production maintenance automation, that can produce silent breakage with limited forensic visibility.
# 清理临时文件
rm -rf /tmp/* 2>/dev/null
rm -rf /var/tmp/* 2>/dev/null
echo "=== 清理完成 ==="
df -h
Automated rm -rf /var/tmp/* 2>/dev/null is dangerous because it recursively deletes potentially important temporary data and conceals failures. In production maintenance automation, that can produce silent breakage with limited forensic visibility.
# 清理临时文件
rm -rf /tmp/* 2>/dev/null
rm -rf /var/tmp/* 2>/dev/null
echo "=== 清理完成 ==="
df -h
Automated rm -rf /var/tmp/* 2>/dev/null is dangerous because it recursively deletes potentially important temporary data and conceals failures. In production maintenance automation, that can produce silent breakage with limited forensic visibility.
# 清理临时文件
rm -rf /tmp/* 2>/dev/null
rm -rf /var/tmp/* 2>/dev/null
echo "=== 清理完成 ==="
df -h
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# 创建普通用户(禁止直接用 root)
useradd -m -s /bin/bash username
echo "username:StrongPassword123!" | chpasswd
usermod -aG sudo username
# 配置 SSH 密钥
mkdir -p ~/.ssh
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
mkdir -p ~/.ssh chmod 700 ~/.ssh echo "你的公钥" > ~/.ssh/authorized_keys chmod 600 ~/.ssh/authorized_keys
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
mkdir -p ~/.ssh chmod 700 ~/.ssh echo "你的公钥" > ~/.ssh/authorized_keys chmod 600 ~/.ssh/authorized_keys
### 3. SSH 加固
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
} EOF
systemctl enable --now nftables
### 5. 性能优化
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
} EOF
systemctl enable --now nftables
### 5. 性能优化
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
} EOF
systemctl enable --now nftables
### 5. 性能优化
No suspicious patterns detected.