Back to skill

Security audit

VPS 维护配置

Security checks for vulnerabilities and agentic risk

Overview

This VPS maintenance skill is broadly aligned with server administration, but its copy-paste commands can lock users out, create a known sudo password, replace package sources, and delete important system state without enough safeguards.

Review carefully before installing or using this skill. Do not copy its account, SSH, firewall, APT, or cleanup commands directly on a production VPS. Replace the hardcoded password workflow with interactive or key-only setup, target the intended user's authorized_keys explicitly, test SSH in a second session before disabling password login or enabling a drop firewall, prefer HTTPS and distribution-matched package sources, and avoid broad unattended deletion of logs, temp directories, caches, packages, or kernels.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:37
Finding

Predictable Hardcoded Password for a Sudo-Capable Account

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:42
Finding

Destructive SSH Key Replacement Can Configure the Wrong Account and Cause Remote Lockout

Content
View full analysis
~/.ssh/authorized_keys chmod 600 ~/.ssh/authorized_keys ``` The Skill subsequently disables password authentication and restarts SSH: ```bash cat >> /etc/ssh/sshd_config <` redirection replaces the complete `authorized_keys` file rather than safely adding a validated key. Existing authorized keys are therefore destroyed. If the literal placeholder is copied, the resulting file does not contain a valid public key. The procedure then appends SSH directives, disables password authentication, and restarts the SSH service without: - Confirming the intended target account. - Applying correct file ownership. - Validating the public-key format. - Checking the resulting configuration with `sshd -t`. - Verifying key-based access in a separate active session. - Detecting conflicting directives already present in the SSH configuration. These combined behaviors can eliminate all valid remote authentication paths. ### Attack Path 1. The administrator runs the procedure from a root shell. 2. `~/.ssh` resolves to root's SSH directory rather than the new user's home directory. 3. The redirection truncates root's existing `authorized_keys` file. 4. The placehol ...[truncated 932 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:16
Finding

System Package Sources Are Replaced with Plaintext HTTP Mirrors

Content
View full analysis
/etc/apt/sources.list <
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:170
Finding

Indiscriminate Non-Interactive Cleanup Can Delete Active State and Forensic Records

Content
View full analysis
/dev/null | grep '^ii' | grep -v "$(uname -r | sed 's/-.*//')" | awk '{print $2}' | xargs apt-get -y purge 2>/dev/null journalctl --vacuum-time=7d find /var/log -type f -name "*.log" -mtime +7 -delete 2>/dev/null find /var/log -type f -name "*.gz" -mtime +30 -delete 2>/dev/null find /var/log -type f -name "*.old" -delete 2>/dev/null rm -rf /tmp/* 2>/dev/null rm -rf /var/tmp/* 2>/dev/null rm -rf ~/.cache/* 2>/dev/null ``` The recurring cleanup script repeats the principal unsafe operations: ```bash apt-get autoremove -y find /var/log -type f -name "*.log" -mtime +7 -delete 2>/dev/null rm -rf /tmp/* 2>/dev/null rm -rf /var/tmp/* 2>/dev/null ``` ### Technical Analysis The cleanup operations are executed non-interactively and use broad path and filename patterns without checking whether files are currently in use or managed by another subsystem. Potentially unsafe behaviors include: - `apt-get autoremove -y` removes packages without an operator reviewing the proposed transaction. - The old-kernel pipeline relies on string matching against the running kernel and suppresses errors, increasing the chance that an unexpected package set is purged without visible diagnostics. - Direct deletion under `/var/log` bypasses application-specific retention and rotation rules and can erase security or incident-response evidence. - Clearing `/tmp` and `/var/tmp` can remove active sockets, lock files, session data, staged updates, or application state. - Clearing `~/.cache` affects whichever account runs the procedure, commonly root, without establishing that cached data is safe to remove. - Redirecting errors to `/dev/null` conceals parti ...[truncated 1426 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (28)

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 45)May include surrounding context.

配置 SSH 密钥

mkdir -p ~/.ssh chmod 700 ~/.ssh echo "你的公钥" > ~/.ssh/authorized_keys chmod 600 ~/.ssh/authorized_keys

text

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 46)May include surrounding context.

配置 SSH 密钥

mkdir -p ~/.ssh chmod 700 ~/.ssh echo "你的公钥" > ~/.ssh/authorized_keys chmod 600 ~/.ssh/authorized_keys

text

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · SKILL.md (reported line 45)May include surrounding context.

CODENAME}-updates main contrib non-free non-free-firmware EOF

国外用户用官方源

deb https://deb.debian.org/debian/ ${CODENAME} main ...

apt update

text

### 2. 账户安全

```bash
# 创建普通用户(禁止直接用 root)
useradd -m -s /bin/bash username
echo "username:StrongPassword123!" | chpasswd
usermod -aG sudo username

# 配置 SSH 密钥
mkdir -p ~/.ssh
chmod 700 ~/.ssh
echo "你的公钥" > ~/.ssh/authorized_keys
chmod 600 ~/.ssh/authorized_keys

3. SSH 加固

bash
# 备份配置
cp /etc/ssh/sshd_config /etc/ssh/sshd_config.backup

# 修改默认端口(防扫描)
sed -i 's/^#*Port .*/Port 54321/' /etc/ssh/sshd_config

# 加固配置
cat >> /etc/ssh/sshd_config <<EOF
PasswordAuthentication no
PermitRootLogin prohibit-password
PubkeyAuthentication yes
LoginGraceTime 30
MaxAuthTries 3
EOF

systemctl restart ssh

4. 防火墙 (nftables)

bash
# 安装 nftables(替代 ufw)
apt-get install -y nftables

# 配置规则(只开放 SSH�

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The SSH hardening and firewall steps change the SSH port, disable password authentication, and apply a default-drop firewall policy with only the new SSH port allowed, but they do not require validation before restart or enablement. If the key is not installed correctly, the port is wrong, or the cloud provider firewall does not match, the user can be locked out of the server entirely.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

The exact command rm -rf /tmp/* 2>/dev/null suppresses errors while recursively deleting all visible contents of /tmp, which reduces operator visibility into what failed or was removed. Error suppression combined with forceful deletion makes accidental impact harder to detect and recover from.

Content

Scanner excerpt · SKILL.md (reported line 184)May include surrounding context.

md
find /var/log -type f -name "*.old" -delete 2>/dev/null

# 4. 清理临时文件
rm -rf /tmp/* 2>/dev/null
rm -rf /var/tmp/* 2>/dev/null

# 5. 清理用户缓存

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
87% confidence
Finding

The exact command rm -rf /tmp/* 2>/dev/null suppresses errors while recursively deleting all visible contents of /tmp, which reduces operator visibility into what failed or was removed. Error suppression combined with forceful deletion makes accidental impact harder to detect and recover from.

Content

Scanner excerpt · SKILL.md (reported line 184)May include surrounding context.

md
find /var/log -type f -name "*.old" -delete 2>/dev/null

# 4. 清理临时文件
rm -rf /tmp/* 2>/dev/null
rm -rf /var/tmp/* 2>/dev/null

# 5. 清理用户缓存

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

The exact command rm -rf /tmp/* 2>/dev/null suppresses errors while recursively deleting all visible contents of /tmp, which reduces operator visibility into what failed or was removed. Error suppression combined with forceful deletion makes accidental impact harder to detect and recover from.

Content

Scanner excerpt · SKILL.md (reported line 184)May include surrounding context.

md
find /var/log -type f -name "*.old" -delete 2>/dev/null

# 4. 清理临时文件
rm -rf /tmp/* 2>/dev/null
rm -rf /var/tmp/* 2>/dev/null

# 5. 清理用户缓存

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

rm -rf /var/tmp/* 2>/dev/null combines broad deletion with hidden errors, making unsafe cleanup less observable. On production VPS systems, this can mask permission issues or partial deletion states while still damaging application workflows.

Content

Scanner excerpt · SKILL.md (reported line 185)May include surrounding context.

md
# 4. 清理临时文件
rm -rf /tmp/* 2>/dev/null
rm -rf /var/tmp/* 2>/dev/null

# 5. 清理用户缓存
rm -rf ~/.cache/* 2>/dev/null

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
89% confidence
Finding

rm -rf /var/tmp/* 2>/dev/null combines broad deletion with hidden errors, making unsafe cleanup less observable. On production VPS systems, this can mask permission issues or partial deletion states while still damaging application workflows.

Content

Scanner excerpt · SKILL.md (reported line 185)May include surrounding context.

md
# 4. 清理临时文件
rm -rf /tmp/* 2>/dev/null
rm -rf /var/tmp/* 2>/dev/null

# 5. 清理用户缓存
rm -rf ~/.cache/* 2>/dev/null

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

rm -rf /var/tmp/* 2>/dev/null combines broad deletion with hidden errors, making unsafe cleanup less observable. On production VPS systems, this can mask permission issues or partial deletion states while still damaging application workflows.

Content

Scanner excerpt · SKILL.md (reported line 185)May include surrounding context.

md
# 4. 清理临时文件
rm -rf /tmp/* 2>/dev/null
rm -rf /var/tmp/* 2>/dev/null

# 5. 清理用户缓存
rm -rf ~/.cache/* 2>/dev/null

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

rm -rf ~/.cache/* 2>/dev/null silently removes all cache contents for the current user while hiding failures, which can obscure troubleshooting and unexpectedly reset tool state. The danger is moderate to low, but it is still an unsafe blanket operation in generic guidance.

Content

Scanner excerpt · SKILL.md (reported line 188)May include surrounding context.

rm -rf /var/tmp/* 2>/dev/null

5. 清理用户缓存

rm -rf ~/.cache/* 2>/dev/null

text

---

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

rm -rf ~/.cache/* 2>/dev/null silently removes all cache contents for the current user while hiding failures, which can obscure troubleshooting and unexpectedly reset tool state. The danger is moderate to low, but it is still an unsafe blanket operation in generic guidance.

Content

Scanner excerpt · SKILL.md (reported line 188)May include surrounding context.

rm -rf /var/tmp/* 2>/dev/null

5. 清理用户缓存

rm -rf ~/.cache/* 2>/dev/null

text

---

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

rm -rf ~/.cache/* 2>/dev/null silently removes all cache contents for the current user while hiding failures, which can obscure troubleshooting and unexpectedly reset tool state. The danger is moderate to low, but it is still an unsafe blanket operation in generic guidance.

Content

Scanner excerpt · SKILL.md (reported line 188)May include surrounding context.

rm -rf /var/tmp/* 2>/dev/null

5. 清理用户缓存

rm -rf ~/.cache/* 2>/dev/null

text

---

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Including rm -rf /tmp/* 2>/dev/null inside a scheduled cleanup script creates a recurring destructive action with suppressed errors, increasing the chance of unnoticed service impact. This is especially risky on multi-service VPS hosts where /tmp is actively used.

Content

Scanner excerpt · SKILL.md (reported line 223)May include surrounding context.

md
find /var/log -type f -name "*.log" -mtime +7 -delete 2>/dev/null

# 清理临时文件
rm -rf /tmp/* 2>/dev/null
rm -rf /var/tmp/* 2>/dev/null

echo "=== 清理完成 ==="

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
87% confidence
Finding

Including rm -rf /tmp/* 2>/dev/null inside a scheduled cleanup script creates a recurring destructive action with suppressed errors, increasing the chance of unnoticed service impact. This is especially risky on multi-service VPS hosts where /tmp is actively used.

Content

Scanner excerpt · SKILL.md (reported line 223)May include surrounding context.

md
find /var/log -type f -name "*.log" -mtime +7 -delete 2>/dev/null

# 清理临时文件
rm -rf /tmp/* 2>/dev/null
rm -rf /var/tmp/* 2>/dev/null

echo "=== 清理完成 ==="

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Including rm -rf /tmp/* 2>/dev/null inside a scheduled cleanup script creates a recurring destructive action with suppressed errors, increasing the chance of unnoticed service impact. This is especially risky on multi-service VPS hosts where /tmp is actively used.

Content

Scanner excerpt · SKILL.md (reported line 223)May include surrounding context.

md
find /var/log -type f -name "*.log" -mtime +7 -delete 2>/dev/null

# 清理临时文件
rm -rf /tmp/* 2>/dev/null
rm -rf /var/tmp/* 2>/dev/null

echo "=== 清理完成 ==="

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Automated rm -rf /var/tmp/* 2>/dev/null is dangerous because it recursively deletes potentially important temporary data and conceals failures. In production maintenance automation, that can produce silent breakage with limited forensic visibility.

Content

Scanner excerpt · SKILL.md (reported line 224)May include surrounding context.

md
# 清理临时文件
rm -rf /tmp/* 2>/dev/null
rm -rf /var/tmp/* 2>/dev/null

echo "=== 清理完成 ==="
df -h

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
89% confidence
Finding

Automated rm -rf /var/tmp/* 2>/dev/null is dangerous because it recursively deletes potentially important temporary data and conceals failures. In production maintenance automation, that can produce silent breakage with limited forensic visibility.

Content

Scanner excerpt · SKILL.md (reported line 224)May include surrounding context.

md
# 清理临时文件
rm -rf /tmp/* 2>/dev/null
rm -rf /var/tmp/* 2>/dev/null

echo "=== 清理完成 ==="
df -h

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Automated rm -rf /var/tmp/* 2>/dev/null is dangerous because it recursively deletes potentially important temporary data and conceals failures. In production maintenance automation, that can produce silent breakage with limited forensic visibility.

Content

Scanner excerpt · SKILL.md (reported line 224)May include surrounding context.

md
# 清理临时文件
rm -rf /tmp/* 2>/dev/null
rm -rf /var/tmp/* 2>/dev/null

echo "=== 清理完成 ==="
df -h

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 40)May include surrounding context.

md
# 创建普通用户(禁止直接用 root)
useradd -m -s /bin/bash username
echo "username:StrongPassword123!" | chpasswd
usermod -aG sudo username

# 配置 SSH 密钥
mkdir -p ~/.ssh

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

配置 SSH 密钥

mkdir -p ~/.ssh chmod 700 ~/.ssh echo "你的公钥" > ~/.ssh/authorized_keys chmod 600 ~/.ssh/authorized_keys

text

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 46)May include surrounding context.

mkdir -p ~/.ssh chmod 700 ~/.ssh echo "你的公钥" > ~/.ssh/authorized_keys chmod 600 ~/.ssh/authorized_keys

text

### 3. SSH 加固

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 93)May include surrounding context.

} EOF

systemctl enable --now nftables

text

### 5. 性能优化

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 135)May include surrounding context.

} EOF

systemctl enable --now nftables

text

### 5. 性能优化

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 155)May include surrounding context.

} EOF

systemctl enable --now nftables

text

### 5. 性能优化

Static analysis

No suspicious patterns detected.