Back to skill

Security audit

Nginx Config

Security checks for vulnerabilities and agentic risk

Overview

This skill mainly generates Nginx configuration, but it also includes an under-disclosed helper that reads host status/log data and persistently records user arguments.

Review before installing. Use the Nginx generator only with trusted, validated inputs, and inspect generated config before deployment. Be aware that the bundled nginx-config helper can read local system information and recent syslog entries and will persist command arguments in a local history file.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/script.sh:31
Finding

Undisclosed Access to System Information and System Logs

Content
View full analysis
/dev/null || echo "uptime: unknown")" _log "status" "${1:-}" } cmd_check() { echo " CPU: $(grep -c processor /proc/cpuinfo 2>/dev/null || echo "?") cores Mem: $(free -h 2>/dev/null | awk "/Mem/{print \$3"/"\$2}" || echo "?")" _log "check" "${1:-}" } cmd_logs() { echo " Recent: $(tail -5 /var/log/syslog 2>/dev/null || echo "no access")" _log "logs" "${1:-}" } cmd_info() { uname -a 2>/dev/null; echo " Disk: $(df -h / 2>/dev/null | tail -1)" _log "info" "${1:-}" } ``` ### Technical Analysis The public Skill documentation describes an Nginx configuration generator, but `scripts/script.sh` contains additional commands that inspect the host operating environment. These commands collect: - System uptime - CPU count - Memory consumption - Kernel and operating-system information - Root filesystem usage - Recent entries from `/var/log/syslog` This information is not required to generate Nginx configurations. In particular, system logs may contain hostnames, usernames, service names, network addresses, process failures, and other operational details. The script does not elevate privileges or bypass operating-system access controls. Its access is limited to the permissions of the invoking user. Nevertheless, it crosses the least-privilege boundary of the advertised task by accessing unrelated system information without disclosure in `SKILL.md`. ### Attack Path 1. A user or agent installs the project believing it provides only Nginx configuration-generation capabilities. 2. The user or agent invokes `nginx-config status`, `check`, `logs`, or `info`. 3. The script reads operating-system i ...[truncated 935 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/script.sh:29
Finding

Persistent Plaintext Logging of User-Controlled Arguments

Content
View full analysis
> "$DATA_DIR/history.log"; } ``` Representative logging calls include: ```bash cmd_monitor() { echo " Monitoring: $1" _log "monitor" "${1:-}" } cmd_restart() { echo " systemctl restart $1" _log "restart" "${1:-}" } cmd_backup() { echo " Backup: tar czf backup-$(date +%Y%m%d).tar.gz $1" _log "backup" "${1:-}" } cmd_alert() { echo " Alert: $1 threshold $2" _log "alert" "${1:-}" } ``` ### Technical Analysis The `_log` function appends the first command argument verbatim to a persistent `history.log` file. Command arguments can contain internal paths, service names, host identifiers, monitoring targets, or other operationally sensitive values. The script does not: - Redact sensitive argument content - Inform the user that arguments are persisted - Establish a retention period - Provide a deletion mechanism - Explicitly create the directory with mode `0700` - Explicitly create the history file with mode `0600` Consequently, the effective permissions depend on the process umask and any pre-existing directory or file. Under a permissive umask, other local users may be able to read the history file. The `NGINX_CONFIG_DIR` environment variable can also redirect storage to a caller-selected location. Although the unused `DB` variable points to `data.log`, actual records are written to `history.log`. ### Attack Path 1. A user or automated agent supplies an operationally sensitive value as the first argument to a supported command. 2. The command invokes `_log`. 3. `_log` writes ...[truncated 926 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/nginx.sh:28
Finding

Nginx Directive Injection Through Unvalidated Generator Parameters

Content
View full analysis
Remediation
View remediation
&2 return 1 fi } ``` 7. Do not rely on generic escaping alone. Generate each Nginx grammar element from validated components because hostname, path, port, and upstream fields have different valid syntax. 8. Write generated configuration to a protected temporary file and run `nginx -t -c ` before presenting it for deployment. 9. Require explicit human approval before installing or reloading a generated configuration. 10. Add negative tests covering newline injection, semicolon injection, brace injection, malformed ports, invalid hostnames, and unsafe paths. ]]>
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/nginx.sh (reported line 346)May include surrounding context.

sh
# ---- 禁止危险访问 ----

# 禁止访问隐藏文件(.git, .env 等)
location ~ /\. {
    deny all;
    access_log off;

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest description includes substantial Chinese-language content alongside English, but the skill does not state that language is selectable or user-driven. This can violate language/locale policy expectations when a skill presents or assumes a specific language without explicit opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This shell script contains extensive natural-language output and inline guidance in Chinese, including the usage/help text and generated configuration comments. Under the policy rule, forcing a specific language without user opt-in is a locale/language policy violation because users are not given an alternative language or a documented reason for the restriction.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/nginx.sh (reported line 125)May include surrounding context.

sh
# Generated: $(date '+%Y-%m-%d %H:%M:%S')
# ============================================
# 先用 certbot 获取证书:
#   sudo certbot certonly --nginx -d ${domain} -d www.${domain}

# HTTP → HTTPS 重定向
server {

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The name and help text describe the tool as "nginx-config" and a system operations/monitoring tool, which implies commands like restart, backup, and config would act on nginx-related resources. In reality, commands such as restart and backup merely echo sample shell commands, while others expose generic host information like uname, disk, and syslog, creating a meaningful divergence between the documented intent and actual behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The script silently records command usage and arguments to a history file under the user's data directory without disclosure or consent. If users pass sensitive values as arguments, those values may be persisted in plaintext and later exposed to other local users, backups, support bundles, or forensic collection.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.