安全决策报告

agent4-io

纯文档型技能,通过 MCP 连接 agent4.io 平台。存在远程脚本执行(curl|sh)风险,但数据外泄行为未发现。

安装决策优先 来源: ClawHub 扫描时间: 4 小时前
文件 1
IOC 21
越权项 1
发现 3
最直接的威胁证据
01
用户读取 SKILL.md,被引导执行安装命令 初始入口 · SKILL.md
02
install.sh 脚本被下载并通过管道执行(curl|sh),授予远程服务器代码执行权限 权限提升 · SKILL.md
03
安装脚本可能修改本地文件系统、建立持久化或执行其他未声明操作(取决于 install.sh 内容) 最终危害 · 未知(install.sh 未公开)

为什么得出这个结论

3/4 个维度触发
阻止
声明与实际能力

发现 1 项声明之外的能力或越权行为。

阻止
隐藏执行与外联

提取到 1 个高危 IOC 或外联信号。

阻止
攻击链与高危发现

报告包含 3 步攻击链,另有 1 项高危或严重发现。

复核
依赖与供应链卫生

没有完整依赖信息,供应链判断需要保留弹性。

攻击链

01
用户读取 SKILL.md,被引导执行安装命令

初始入口 · SKILL.md:226

02
install.sh 脚本被下载并通过管道执行(curl|sh),授予远程服务器代码执行权限

权限提升 · SKILL.md:226

03
安装脚本可能修改本地文件系统、建立持久化或执行其他未声明操作(取决于 install.sh 内容)

最终危害 · 未知(install.sh 未公开)

风险分是怎么被拉高的

远程脚本执行 +25

SKILL.md:226 包含 curl -fsSL https://api.agent4.io/v1/integration/install.sh | sh,允许远程服务器执行任意命令

安装脚本内容不透明 +15

install.sh 源码未公开,用户无法验证安装时实际执行了什么操作

文档透明度较高 +-10

明确声明数据发送到 agent4.io、只使用 API key、不访问本地文件

无可疑凭证收割 +-5

代码为纯文档,无脚本执行环境变量枚举

最关键的证据

高危 代码执行

远程脚本执行(curl|sh)

文档第226行包含安装命令 curl -fsSL https://api.agent4.io/v1/integration/install.sh | sh,这允许远程服务器在本地执行任意 shell 命令。虽然声称只用于安装技能,但 install.sh 内容未公开验证。

SKILL.md:226
要求 agent4.io 公开 install.sh 源码,或使用本地验证方式安装技能
中危 供应链

安装脚本源码不可审计

用户无法验证安装脚本实际执行了什么操作(修改哪些文件、安装哪些依赖、是否建立持久化等)

SKILL.md:226
建议 agent4.io 将 install.sh 源码纳入文档审查范围
低危 文档欺骗

数据流向透明但存在盲区

文档明确说明数据发送到 agent4.io,但对于安装时脚本可能执行的操作描述不充分

SKILL.md:77
补充安装过程的完整说明

声明能力 vs 实际能力

文件系统 通过
声明 NONE
推断 NONE
SKILL.md 明确声明不读取本地文件,MCP 工具设计禁止文件访问
网络访问 通过
声明 READ
推断 READ
SKILL.md 声明传输数据到 agent4.io API
命令执行 阻止
声明 NONE
推断 ADMIN
curl|sh 安装命令允许远程执行任意 shell 命令(SKILL.md:226)
环境变量 通过
声明 NONE
推断 NONE
SKILL.md 声明不读取其他环境变量

可疑产物与外联

严重 危险命令
curl -fsSL https://api.agent4.io/v1/integration/install.sh | sh

SKILL.md:226

中危 外部 URL
https://agent4.io/cookbook

SKILL.md:4

中危 外部 URL
https://api.agent4.io/v1/mcp

SKILL.md:27

中危 外部 URL
https://agent4.io/cookbook.

SKILL.md:38

中危 外部 URL
https://console.agent4.io/#/knowledge-bases/

SKILL.md:169

中危 外部 URL
https://console.agent4.io/#/agents/

SKILL.md:170

中危 外部 URL
https://console.agent4.io/#/skills/

SKILL.md:171

中危 外部 URL
https://console.agent4.io/#/storylines/

SKILL.md:172

中危 外部 URL
https://console.agent4.io/#/mcp/

SKILL.md:173

中危 外部 URL
https://api.agent4.io/v1/integration/install.sh

SKILL.md:226

中危 外部 URL
https://api.telegram.org/bot$BOT_TOKEN/setMyCommands

SKILL.md:282

中危 外部 URL
https://agent4.io/api.md

SKILL.md:313

依赖与供应链

没有结构化依赖告警。

文件构成

1 个文件 · 1110 行
Markdown 1 个文件 · 1110 行
需关注文件 · 1
SKILL.md Markdown · 1110 行
远程脚本执行(curl|sh) · 安装脚本源码不可审计 · 数据流向透明但存在盲区 · curl -fsSL https://api.agent4.io/v1/integration/install.sh | sh · https://agent4.io/cookbook · https://api.agent4.io/v1/mcp · https://agent4.io/cookbook. · https://console.agent4.io/#/knowledge-bases/ · https://console.agent4.io/#/agents/ · https://console.agent4.io/#/skills/ · https://console.agent4.io/#/storylines/ · https://console.agent4.io/#/mcp/ · https://api.agent4.io/v1/integration/install.sh · https://api.telegram.org/bot$BOT_TOKEN/setMyCommands · https://agent4.io/api.md · https://console.agent4.io/#/agents/Support · https://acme.com/pricing?ref=x · https://console.agent4.io/#/page-contexts · https://console.agent4.io · https://api.agent4.io/v1 · https://tools.example.com/mcp · https://console.agent4.io/#/usage · https://cdn.example.com/brand/mark-512.png · https://console.agent4.io/#/knowledge-bases/Company%20policy

安全亮点

文档透明度较高,明确声明数据流向
声明不读取本地文件(通过 MCP 工具设计实现)
声明只使用 agent4.io API key,不枚举环境变量
纯文档型技能,无内联恶意代码
无凭证收割、base64 混淆、eval 等高危模式