T06 · System Persistence
- Location
README.md:91- Finding
Optional system-wide persistence exceeds the widget's minimum privilege requirements
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a real desktop system monitor, but it has review-worthy risks because it auto-installs a Python package and runs a localhost web server that can expose more local data than the widget needs.
Install only if you are comfortable running a local web monitor. Prefer installing psutil yourself in a virtual environment, do not run the launcher with sudo, start it from a directory that contains no sensitive files, and avoid enabling the systemd autostart service unless you specifically want persistent startup behavior and know how to remove it.
README.md:91Optional system-wide persistence exceeds the widget's minimum privilege requirements
scripts/start.sh:13Launcher automatically installs an unpinned dependency into the active Python environment
scripts/widget-web.py:239Fallback request handling exposes files from the server's working directory
scripts/widget-web.py:79Wildcard CORS permits cross-origin access to local system telemetry
The skill is presented as a simple desktop monitoring widget, but the described implementation also starts a local HTTP server, exposes endpoints, and opens a browser-based interface. This mismatch is dangerous because users and reviewers may grant trust based on the benign description while overlooking additional execution and network behavior.
The file presents all user-facing instructions and descriptions in Chinese, and does not indicate that users may choose another language or locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
pip3 install psutil
sudo apt install python3-tk
## 使用方法
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
pip3 install psutil
sudo apt install python3-tk
## 使用方法
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
启用服务:
systemctl enable monitor-widget
systemctl start monitor-widget
The skill appears to use network-capable behavior without declaring any tool scope or allowed-tools boundaries. Even if the HTTP server is intended to be local, undeclared network capability expands the attack surface, weakens least-privilege controls, and makes review and containment harder.
The skill description and usage instructions are entirely in Chinese, including the prescribed invocation phrases, with no indication that other languages are supported or that Chinese is a justified locale requirement. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.
Broad trigger phrases like asking about system status or resource usage can collide with normal conversation and cause the skill to activate unintentionally. Unintended activation matters more here because the skill may launch UI elements or start local services, producing side effects without clear user intent.
The startup script automatically installs a Python package at runtime even though the skill is presented as a simple desktop monitoring widget. Installing software modifies the host environment, may pull code from remote package indexes, and expands the trust boundary without explicit user approval.
A system resource display widget does not inherently justify silently fetching and installing packages during execution. This creates unnecessary supply-chain and environment-integrity risk because running the widget can trigger network access and arbitrary third-party code installation.
The script performs automatic pip installation without an explicit warning or confirmation from the user. In context, this makes the widget more dangerous because a low-risk monitoring tool unexpectedly changes the system and executes package installation logic, which could be abused through package source compromise or misconfiguration.
The script presents its title, status text, and console messages in Chinese, which effectively forces a specific language for users regardless of their locale. The policy allows locale constraints when they are opt-in or clearly justified, but this file does not provide such a choice or explanation.
The script does more than render a local desktop widget: it starts an HTTP server and exposes live host telemetry over a browser-accessible endpoint. Even though it binds to 127.0.0.1, any local process and, with wildcard CORS, any website able to induce requests from the local browser can potentially read this data, which expands exposure beyond a normal desktop-only widget.
The /data endpoint returns system monitoring information and explicitly sets Access-Control-Allow-Origin: *, which permits arbitrary web origins to read the response if they can reach the local service. This weakens the browser's same-origin protections and can enable cross-origin collection of host state such as CPU, memory, disk, uptime, and process count.
The manifest and module docstring describe a desktop monitoring floating widget, which implies the application should launch and show live resource data. However, main() only instantiates MonitorWidget and never calls update_data(), so the monitoring loop and mainloop() in L223-L255 are never reached during normal execution.
The script's comments and user-facing echo messages are written in Chinese, which imposes a specific language on the user without offering a choice or documenting a locale-specific requirement. This can violate language or locale policy when no opt-in or justification is provided.
The inline output claims '窗口会自动打开浏览器' as part of the script's behavior, yet this shell script contains no browser-launching logic and only executes the Python file. That statement may be true only if the called Python program does it, so within this file the documentation actively overstates what the code shown actually does.
This code starts a local HTTP server and automatically opens a browser to consume data from it, which is a network operation that transmits system information such as CPU, memory, disk, temperature, uptime, and process count. Although it prints the access URL, there is no explicit warning or disclosure that system telemetry is being served over HTTP.
The module docstring and later UI strings present the skill as Chinese-language by default, with no indication that users can opt into another language or that the widget is intentionally limited to a Chinese-speaking context. This matches the policy concern for language/locale constraints expressed in natural-language content.
No suspicious patterns detected.