T06 · System Persistence
- Location
SKILL.md:90- Finding
Persistent Auto-Start Daemon and Scheduled Update Mechanism
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 90; related persistence references at lines 26, 48, 127, and 133
Vulnerability Type: System persistence through an auto-start daemon and Linux crontab registration
Risk Level: HighRelevant documentation excerpt translated into English:
text - After installation, a system daemon is automatically created to check the official update source every 30 minutes.The document also states that the updater starts at boot and that Linux crontab startup configuration was added.
Technical Analysis
The recommended installation creates a persistent system daemon, while the changelog explicitly identifies Linux crontab as an auto-start mechanism. These mechanisms survive the original Skill run and subsequent user sessions.
Persistent execution is relevant to the declared automatic-update functionality, but it exceeds the minimum privileges and persistence required for manual update checks. The documentation does not make persistence clearly optional, identify the exact service or crontab entries, describe execution identities and permissions, or explain how update checks are isolated from privileged installation operations.
Because the daemon periodically contacts a remote update source and the updater is expected to modify dependencies, compromise of either the updater or its source could turn the legitimate startup mechanism into durable privileged execution.
Attack Path
- A user installs the updater and enables or accepts its documented startup behavior.
- The installer creates an auto-start daemon or Linux crontab entry.
- The persistent process starts automatically across reboots and checks a remote update source every 30 minutes.
- An attacker compromises or substitutes the updater, update source, or retrieved package.
- The persistent process retrieves or processes the attacker-controlled update.
- Malicious changes continue to exec ...[truncated 529 chars]
- Remediation
View remediation
Remediation Suggestions
- Make startup persistence explicitly opt-in rather than part of the default installation.
- Default to user-initiated checks or a documented, user-level scheduler where automatic checks are required.
- Run network checks and version comparisons as an unprivileged account.
- Elevate only for the narrowly scoped file operations that genuinely require system privileges.
- Document the exact Windows service, macOS launch item, Linux service, and crontab entries created.
- Use restrictive service permissions and prevent unprivileged users from modifying executables, configuration, or update metadata used by the daemon.
- Separate update download, signature verification, and privileged installation into distinct stages.
- Provide commands for inspecting, disabling, and completely removing all persistence entries.
- Record update origin, verified version, signature status, and installation result in an auditable log.
