3x-ui-setup
Fail
Audited by Gen Agent Trust Hub on Jun 16, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [REMOTE_CODE_EXECUTION]: Downloads the 3x-ui installation script from a community GitHub repository (
github.com/mhsanaei/3x-ui) and executes it viabash. - [REMOTE_CODE_EXECUTION]: Fetches and executes the
RealiTLScannerbinary directly from its GitHub release page (github.com/XTLS/RealiTLScanner). - [REMOTE_CODE_EXECUTION]: Executes the
acme.shinstallation script by piping a remote download directly into a shell (curl ... | sh). - [COMMAND_EXECUTION]: Utilizes
sudoto perform deep system modifications, including editing/etc/ssh/sshd_config, managing firewall rules withufw, and applying kernel hardening viasysctl. - [COMMAND_EXECUTION]: Injects user-provided variables (e.g., server IP, username, password) directly into shell command templates, creating a potential surface for command injection if malformed input is provided.
- Ingestion points: User-supplied VPS credentials and configuration parameters gathered in
SKILL.md. - Boundary markers: No delimiters or escape sequences are used to isolate user data from the command structure.
- Capability inventory: The skill uses the
Bashtool with root privileges (viasudo) across multiple files. - Sanitization: There is no evidence of input validation or sanitization before interpolation into shell commands.
- [EXTERNAL_DOWNLOADS]: Downloads various components, including the 3x-ui panel, networking tools, and SSL management scripts from external repositories and URLs.
Recommendations
- HIGH: Downloads and executes remote code from: https://127.0.0.1:${PANEL_PORT}/{web_base_path}/panel/api/inbounds/list, https://raw.githubusercontent.com/mhsanaei/3x-ui/master/install.sh, https://github.com/XTLS/RealiTLScanner/releases/latest/download/RealiTLScanner-linux-${SA} - DO NOT USE without thorough review
Audit Metadata