Back to skill

Security audit

Rssh2 - SSH远程自动化工具

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real SSH automation tool, but it needs review because it can run remote commands, move/delete files, and open tunnels while lacking key SSH safety controls.

Install only if you intend to let this skill operate on SSH hosts you control. Use a least-privilege account, avoid password auth and root examples, add or require SSH host-key verification before using it with sensitive systems, avoid remote wildcard tunnel binds unless explicitly needed, and treat delete/sync/remote command examples as production-impacting operations.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
index.js:72
Finding

SSH Server Identity Is Not Verified in the Primary Connection

Content
View full analysis

Vulnerability Details

File Location: index.js:72-80
Vulnerability Type: Missing SSH host-key verification
Risk Level: High

js
client.connect({
  host: this.config.host,
  port: this.config.port,
  username: this.config.username,
  password: this.config.password,
  privateKey,
  passphrase: this.config.passphrase,
  keepaliveInterval: this.config.keepaliveInterval,
  readyTimeout: this.config.timeout
});

Technical Analysis

The primary SSH connection does not configure hostVerifier or otherwise validate the server's host-key fingerprint against a trusted value. SSH encryption without server identity verification does not prevent an attacker who can redirect or intercept the connection from impersonating the configured server.

This is particularly significant because the connection can carry passwords, administrative commands, command output, uploaded files, and downloaded files. The private key itself is not transmitted to the server, but the resulting SSH session can still be intercepted or manipulated when the endpoint is not authenticated.

Attack Path

  1. A user configures the Skill to connect to an SSH server.
  2. An attacker capable of DNS poisoning, routing manipulation, or network interception redirects the connection.
  3. The attacker presents an arbitrary SSH host key.
  4. Because the client does not compare that key with a trusted fingerprint, the connection can proceed to the attacker-controlled endpoint.
  5. The attacker can capture password authentication, observe submitted commands and data, return forged output, or manipulate file transfers.

Impact Assessment

Successful exploitation can compromise the confidentiality and integrity of the SSH session. The attacker may obtain a configured password, access transferred files, observe sensitive command output, or influence remote automation decisions by returning falsified results. The effective scope includes al ...[truncated 64 chars]

Remediation
View remediation

Remediation Suggestions

  • Require a trusted SHA-256 host-key fingerprint or known-hosts entry in the connection configuration.
  • Configure ssh2's hostVerifier callback to compare the received host key against that trusted value using a constant-time comparison where applicable.
  • Fail closed if no trusted host key is available rather than silently accepting an unknown server.
  • Provide an explicit, clearly labeled development-only option if first-use enrollment is required.
  • Apply the same verification policy to every SSH connection path in the project.
  • Add tests confirming that connections with unknown or changed host keys are rejected.

T09 · Insecure Skill Coding Practices

Error
Location
session-manager.js:108
Finding

SSH Server Identity Is Not Verified in Pooled Sessions

Content
View full analysis

Vulnerability Details

File Location: session-manager.js:108-116
Vulnerability Type: Missing SSH host-key verification
Risk Level: High

js
client.connect({
  host: this.config.host,
  port: this.config.port || 22,
  username: this.config.username,
  password: this.config.password,
  privateKey,
  passphrase: this.config.passphrase,
  keepaliveInterval: this.options.keepaliveInterval,
  readyTimeout: this.config.timeout || 10000
});

Technical Analysis

Connections created by the session pool independently omit SSH host-key verification. Securing only the primary Rssh2.connect() implementation would therefore be insufficient: commands, SFTP operations, and tunnels using SessionManager would remain vulnerable.

Because the manager can create several pooled connections, an intercepted endpoint may receive multiple authenticated sessions and the operations performed through them.

Attack Path

  1. A caller executes a command, starts an SFTP operation, or creates a tunnel through a manager backed by SessionManager.
  2. SessionManager creates a new SSH connection to the configured hostname.
  3. An attacker redirects or intercepts that connection and presents an untrusted host key.
  4. The manager accepts the endpoint without checking a pinned key.
  5. Operations assigned to the compromised pooled connection are exposed to or manipulated by the attacker.

Impact Assessment

The attacker may compromise commands, command output, SFTP data, passwords, and tunnel traffic handled by pooled connections. The impact covers every feature that obtains its SSH client from SessionManager, including session execution, SFTP, and forwarding.

Remediation
View remediation

Remediation Suggestions

  • Centralize SSH configuration construction so all connection paths enforce the same host-verification policy.
  • Pass a strict hostVerifier to client.connect() and validate it against a configured fingerprint or managed known-hosts store.
  • Reject absent, malformed, unknown, or changed fingerprints.
  • Avoid implementing separate authentication logic in index.js and session-manager.js.
  • Add integration tests for valid, invalid, and rotated host keys across pooled sessions, SFTP, and tunnels.

T09 · Insecure Skill Coding Practices

Warning
Location
tunnel-manager.js:93
Finding

Remote Port Forwarding Uses a Wildcard Default and Reversed API Arguments

Content
View full analysis

Vulnerability Details

File Location: tunnel-manager.js:93-126
Vulnerability Type: Unsafe remote listener configuration and incorrect forwarding API usage
Risk Level: Medium

js
const opts = {
  remotePort: config.remotePort,
  localHost: config.localHost || 'localhost',
  localPort: config.localPort,
  remoteHost: config.remoteHost || '0.0.0.0',
  ...options
};
js
conn.client.forwardIn(tunnel.config.remotePort, tunnel.config.remoteHost, (err) => {
  if (err) {
    reject(err);
    return;
  }

  tunnel.connected = true;
  this.emit('tunnelConnected', tunnel);
  resolve();
});

Technical Analysis

The ssh2.Client.forwardIn() API expects the bind address before the bind port, but the implementation passes remotePort first and remoteHost second. This can cause forwarding to fail or behave unexpectedly.

In addition, the intended remote bind address defaults to 0.0.0.0. If the argument order is corrected without also changing this default, the remote SSH server may expose the forwarded port on every interface, subject to server forwarding policy and network controls. That exceeds the least-exposure default needed for ordinary private tunneling.

Attack Path

  1. A user requests a remote port forward without specifying remoteHost.
  2. The code selects 0.0.0.0 as the intended bind address.
  3. The current reversed arguments cause failure or implementation-dependent behavior.
  4. If the argument order is corrected while retaining the wildcard default, the SSH server requests a listener on all remote interfaces.
  5. When the SSH server and firewall permit it, external systems can connect to that port and reach the service exposed through the tunnel.

Impact Assessment

The current defect makes remote forwarding unreliable. Under a corrected or permissive execution path, the wildcard default can expose a local or internal service to hosts that can reach ...[truncated 274 chars]

Remediation
View remediation

Remediation Suggestions

  • Invoke the API in the documented order:

    js
    conn.client.forwardIn(
      tunnel.config.remoteHost,
      tunnel.config.remotePort,
      callback
    );
    
  • Default the remote bind address to 127.0.0.1 or localhost.

  • Require explicit authorization or an opt-in setting before permitting 0.0.0.0, ::, or another non-loopback address.

  • Validate ports as integers in the range 1 through 65535.

  • Document the interaction with SSH server GatewayPorts settings.

  • Add an integration test that verifies both the actual bind interface and external reachability.

T09 · Insecure Skill Coding Practices

Warning
Location
tunnel-manager.js:61
Finding

Local Port Forwarding Reverses Source and Destination Parameters

Content
View full analysis

Vulnerability Details

File Location: tunnel-manager.js:61-66
Vulnerability Type: Incorrect SSH forwarding destination construction
Risk Level: Medium

js
conn.client.forwardOut(
  tunnel.config.remoteHost,
  tunnel.config.remotePort,
  tunnel.config.localHost,
  tunnel.config.localPort,
  (err, remoteSocket) => {

Technical Analysis

ssh2.Client.forwardOut() expects arguments in the order (sourceAddress, sourcePort, destinationAddress, destinationPort, callback). The code instead puts the requested remote destination in the source fields and uses the local listener address and port as the destination.

As a result, the tunnel does not reliably connect to remoteHost:remotePort as documented. It may fail or cause the SSH server to connect to an unintended address and port on the remote side.

Attack Path

  1. A user starts a local tunnel intended to reach a selected remote service.
  2. A local client connects to the tunnel listener.
  3. The Skill sends the desired destination as SSH forwarding source metadata.
  4. The SSH server interprets localHost:localPort as the actual destination.
  5. Traffic either fails or reaches an unintended service accessible from the SSH server.

Impact Assessment

The primary impact is incorrect network routing and possible unintended access to a remote-side service. The scope is limited by what the authenticated SSH account is permitted to forward to and by services reachable from the SSH server. The bug can also undermine security assumptions when callers believe traffic is being delivered to a different endpoint.

Remediation
View remediation

Remediation Suggestions

  • Pass the intended endpoint in the destination fields:

    js
    conn.client.forwardOut(
      sourceAddress,
      sourcePort,
      tunnel.config.remoteHost,
      tunnel.config.remotePort,
      callback
    );
    
  • Derive source metadata from the accepted local socket, such as localSocket.remoteAddress and localSocket.remotePort, after validating availability.

  • Validate destination hostnames and port ranges.

  • Add an end-to-end test with distinct listener and destination ports to detect parameter reversal.

  • Log the resolved destination without logging credentials or sensitive traffic.

T09 · Insecure Skill Coding Practices

Warning
Location
tunnel-manager.js:207
Finding

Dynamic SOCKS Forwarding Reverses Source and Destination Parameters

Content
View full analysis

Vulnerability Details

File Location: tunnel-manager.js:207-212
Vulnerability Type: Incorrect SSH forwarding destination construction
Risk Level: Medium

js
conn.client.forwardOut(
  targetHost,
  targetPort,
  '127.0.0.1',
  tunnel.config.localPort,
  (err, remoteSocket) => {

Technical Analysis

The SOCKS request supplies targetHost and targetPort as the requested destination, but the implementation places those values in the source fields of forwardOut(). It then sets 127.0.0.1 and the SOCKS listener port as the destination.

This defeats the SOCKS routing request. Rather than connecting to the client-selected endpoint, the SSH server may attempt to connect to its own loopback interface at the local SOCKS listener's port number. The behavior can produce failures or reach an unintended service on the SSH server.

Attack Path

  1. A client connects to the local SOCKS listener and submits a valid SOCKS5 CONNECT request.
  2. The Skill parses the requested host and port.
  3. Those values are passed as SSH source metadata rather than the destination.
  4. The SSH server attempts to connect to 127.0.0.1 at tunnel.config.localPort.
  5. If a service is listening there, traffic may reach that unintended service; otherwise the proxy request fails.

Impact Assessment

The dynamic proxy does not provide the documented routing behavior and may unintentionally access a loopback-only service on the SSH server. The reachable privilege scope is constrained by the remote SSH server and the authenticated account's forwarding permissions, but unintended loopback access can be security-sensitive because such services are often not exposed externally.

Remediation
View remediation

Remediation Suggestions

  • Put the SOCKS-requested endpoint in the destination fields:

    js
    conn.client.forwardOut(
      sourceAddress,
      sourcePort,
      targetHost,
      targetPort,
      callback
    );
    
  • Use the SOCKS client's actual address and port as source metadata where available.

  • Validate SOCKS request lengths before indexing or calling readUInt16BE.

  • Validate destination ports and consider policy-based restrictions for loopback, link-local, metadata-service, and private-network destinations.

  • Add integration tests proving that IPv4 and domain-name SOCKS requests reach the requested endpoint and not an SSH-server loopback service.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (22)

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

该代码块的核心功能确实属于SSH远程自动化的一部分,尤其是会话管理和远程命令执行,与声明中的“会话管理”场景基本一致。但声明明确提到“隧道、文件传输”,而实际代码仅使用 ssh2.Client 建立SSH连接并执行 exec 命令,没有看到 forwardIn/forwardOut、端口转发、代理隧道等实现,也没有任何 SFTP/SCP 或本地/远程文件传输逻辑。代码会读取本地私钥文件,这属于SSH连接的支持性实现细节,不构成额外未声明能力。综合来看,描述比实际能力更宽,存在实质性描述不准确。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents a broader SSH remote automation tool covering session management, tunnels, and remote command execution in addition to file transfer. However, this specific code chunk only provides SFTP-based file and filesystem management on top of an existing session manager connection. It does not implement SSH session management, SSH tunnel creation, or remote command execution. While file transfer is consistent with part of the description, the declared purpose materially overstates what this code chunk actually does, and the code also includes richer remote filesystem operations such as recursive directory upload/download, sync, rename, delete, and stat that are not mentioned explicitly. Therefore this chunk does not accurately match the full declared description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

代码的主要功能与声明中的“建立SSH隧道”部分一致,且没有发现额外越权或无关的危险能力;不过声明描述的是一个更完整的 SSH 自动化工具,包含会话管理、文件传输和远程命令执行等场景,而当前提供的代码块仅覆盖隧道管理。按照描述与实际行为是否准确代表的标准,这属于描述范围明显大于该代码实际能力的情况,因此应判定为不匹配。

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 57)May include surrounding context.

md
host: 'bg.dlna.net',
  port: 38022,
  username: 'root',
  privateKey: '/home/yupeng/.ssh/id_ed25519'
});

// 执行命令

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 57)May include surrounding context.

md
host: 'bg.dlna.net',
  port: 38022,
  username: 'root',
  privateKey: '/home/yupeng/.ssh/id_ed25519'
});

// 执行命令

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The rmdir method can recursively traverse and delete all files and subdirectories under a remote path when recursive is true. There is no confirmation prompt, warning log, or explicit documentation in the file about this irreversible operation, increasing the risk of accidental data loss.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documentation promotes high-impact capabilities—remote command execution, file transfer, tunneling, and deletion—without prominent operational-risk guidance next to those examples. In an automation skill, this can normalize destructive or over-privileged use and increase the chance of accidental misuse against production systems or sensitive hosts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code establishes SSH connections and executes arbitrary remote commands via client.connect and client.exec, which are safety-critical operations affecting remote systems. Although the comments describe functionality, there is no confirmation prompt, user-facing log/print, or explicit warning about these actions in the file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The upload, download, and sync methods perform file-transfer actions that can write or overwrite data on local or remote systems. The file contains only brief capability comments and no visible confirmation, user disclosure, or warning about these potentially impactful operations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The code reads a private key from a filesystem path or directly from configuration data, which is sensitive credential handling. The file contains only developer comments and no user-facing disclosure, prompt, or warning that credential material may be accessed and used for authentication.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This file establishes SSH connections using host credentials and then executes arbitrary remote commands, which are safety-critical operations involving network transmission and subprocess-like remote execution. While the code has internal comments and events, it does not include any user-facing confirmation, warning, logging, or disclosure about connecting to a remote host and running commands.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The delete method removes a remote file via SFTP, but the code provides no confirmation prompt, visible logging, or explicit warning comment describing the destructive action. This is a safety-relevant operation because it can irreversibly remove user or system data on the remote host.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

This code defines SSH authentication inputs including username, private key path, and password, which are sensitive credential-related operations under the warning criteria for code files. Although there are inline labels, they do not warn the user about handling secrets safely, exposure risk, or that the script will use these credentials to connect to a remote host.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code creates remote port forwarding via forwardIn, and the default remoteHost is 0.0.0.0, which can expose a listening port broadly on the remote side. Although the code has internal comments, there is no confirmation prompt, user-visible logging, or other clear disclosure at the point this network-exposing action occurs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The dynamic tunnel implementation starts a SOCKS proxy server and relays arbitrary client traffic through the SSH connection. The file contains code comments, but no user-facing warning, prompt, or visible log message indicates that a proxy listener is being opened and network traffic may be transmitted through it.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The example uses the root account in a quick-start snippet, which encourages privileged remote automation before the later guidance advises against it. Because users often copy examples verbatim, this increases the risk of high-impact mistakes, broader compromise if credentials are stolen, and unsafe operational norms.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The natural-language description and method comments are presented in Chinese, with no indication that the language is optional or that the tool is intentionally restricted to a Chinese-speaking context. This can violate language/locale policy where user-facing skill content should not force a language without opt-in or justification.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 21)May include surrounding context.

json
"author": "OpenClaw",
  "license": "MIT",
  "dependencies": {
    "ssh2": "^1.17.0"
  }
}

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The natural-language documentation in this file is written in Chinese, and there is no indication that the skill is region-specific or that users can choose their preferred language. Under the stated policy, forcing a specific language without opt-in can be a locale-policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The class documentation is written entirely in Chinese and provides no indication that language choice is configurable or user-selected. Under the stated policy, forcing a specific language or locale without opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

Natural-language strings and comments throughout the file are written in Chinese, which effectively forces a specific language for users of the skill. Under the language/locale policy, this is a violation unless the skill offers user choice or clearly documents a justified locale-specific scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The human-readable comments and method descriptions in this file are written in Chinese only, with no indication that language selection is optional or that the tool is intentionally region-specific. Under the stated policy, forcing a specific language without user opt-in can be a locale-policy issue.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.