3x-ui-setup

Fail

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [REMOTE_CODE_EXECUTION]: Downloads the 3x-ui installation script from a community GitHub repository (github.com/mhsanaei/3x-ui) and executes it via bash.
  • [REMOTE_CODE_EXECUTION]: Fetches and executes the RealiTLScanner binary directly from its GitHub release page (github.com/XTLS/RealiTLScanner).
  • [REMOTE_CODE_EXECUTION]: Executes the acme.sh installation script by piping a remote download directly into a shell (curl ... | sh).
  • [COMMAND_EXECUTION]: Utilizes sudo to perform deep system modifications, including editing /etc/ssh/sshd_config, managing firewall rules with ufw, and applying kernel hardening via sysctl.
  • [COMMAND_EXECUTION]: Injects user-provided variables (e.g., server IP, username, password) directly into shell command templates, creating a potential surface for command injection if malformed input is provided.
  • Ingestion points: User-supplied VPS credentials and configuration parameters gathered in SKILL.md.
  • Boundary markers: No delimiters or escape sequences are used to isolate user data from the command structure.
  • Capability inventory: The skill uses the Bash tool with root privileges (via sudo) across multiple files.
  • Sanitization: There is no evidence of input validation or sanitization before interpolation into shell commands.
  • [EXTERNAL_DOWNLOADS]: Downloads various components, including the 3x-ui panel, networking tools, and SSL management scripts from external repositories and URLs.
Recommendations
  • HIGH: Downloads and executes remote code from: https://127.0.0.1:${PANEL_PORT}/{web_base_path}/panel/api/inbounds/list, https://raw.githubusercontent.com/mhsanaei/3x-ui/master/install.sh, https://github.com/XTLS/RealiTLScanner/releases/latest/download/RealiTLScanner-linux-${SA} - DO NOT USE without thorough review
Audit Metadata
Risk Level
HIGH
Analyzed
Jun 16, 2026, 09:16 AM
Security Audit — agent-trust-hub — 3x-ui-setup