pinggy-tunnel
Fail
Audited by Gen Agent Trust Hub on May 16, 2026
Risk Level: CRITICALCOMMAND_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill executes SSH commands that include the flags
-o StrictHostKeyChecking=noand-o UserKnownHostsFile=/dev/null. This configuration bypasses the verification of the remote host's identity, significantly increasing the risk of Man-in-the-Middle (MitM) attacks where an attacker could intercept the tunnel traffic. - [DATA_EXFILTRATION]: Facilitates the creation of public reverse tunnels that map local ports (such as web servers, databases, or MCP endpoints) to the public internet via the
pinggy.ioservice. This represents a data exposure risk as it provides a pathway for external actors to reach services running on the agent's host environment. - [EXTERNAL_DOWNLOADS]: Establishes network connections to the external domain
a.pinggy.ioon port 443 to facilitate the tunnel. Automated scanners flagged severalpinggy.linksubdomains as malicious; while these are likely transient URLs used by third parties on the shared infrastructure, they highlight the risks associated with using public tunnel services for sensitive data.
Recommendations
- CRITICAL: 1 infected file(s) detected - DO NOT USE
- Contains 3 malicious URL(s) - DO NOT USE
Audit Metadata