T05 · Unauthorized Access and Privilege Escalation
- Location
universal_service.py:263- Finding
Mutable service assets can be persisted as a highest-privilege Windows SYSTEM task
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is an auto-start manager, but it installs high-privilege persistent tasks and includes an unrelated publishing script with a hard-coded upload credential.
Install only if you intentionally want a program to run automatically across reboots and you trust the configuration and all files in the package. Review or remove publish_textonly.py, rotate the exposed SkillHub key, avoid SYSTEM/root defaults where possible, and verify that uninstall removes the exact task or plist that was installed.
universal_service.py:263Mutable service assets can be persisted as a highest-privilege Windows SYSTEM task
publish_textonly.py:13Hard-coded SkillHub bearer credential can be included in the uploaded package
install_macos.sh:8macOS wrappers require unnecessary root execution for a user LaunchAgent
universal_service.py:297Unvalidated service names permit macOS plist path traversal and XML injection
uninstall_macos.sh:16macOS uninstall targets the default service instead of the configured installed service
This is a severe description-behavior mismatch: the skill claims to manage OS auto-start services, but the analysis indicates unrelated behavior including collecting local files, packaging them, and uploading them to a remote API using a hardcoded credential. Hidden file collection and exfiltration under the cover of a persistence-management utility is highly suspicious and could directly lead to data theft and unauthorized publishing actions.
This is a severe description-behavior mismatch: the skill claims to manage OS auto-start services, but the analysis indicates unrelated behavior including collecting local files, packaging them, and uploading them to a remote API using a hardcoded credential. Hidden file collection and exfiltration under the cover of a persistence-management utility is highly suspicious and could directly lead to data theft and unauthorized publishing actions.
The provided Windows installer intentionally passes --no-check-admin to the service-management script after its own wrapper-level privilege check. Bypass flags that disable safety validation are dangerous because they can be reused outside the intended wrapper, weakening defense in depth for operations that modify persistence and system startup behavior.
)
:: 安装服务
python "%~dp0universal_service.py" install "%CONFIG_FILE%" --no-check-admin
if %errorLevel% equ 0 (
echo [OK] 安装完成!服务将在下次开机自动启动
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
| **日志记录** | 实时日志输出,支持文件轮转 |
| **健康检查** | 端口/进程检测,确保服务正常运行 |
| **优雅退出** | 支持 SIGTERM/SIGINT 信号处理 |
| **环境变量** | 支持加载 .env 文件 |
## 🔧 使用方式
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
| **日志记录** | 实时日志输出,支持文件轮转 |
| **健康检查** | 端口/进程检测,确保服务正常运行 |
| **优雅退出** | 支持 SIGTERM/SIGINT 信号处理 |
| **环境变量** | 支持加载 .env 文件 |
## 🔧 使用方式
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
| **日志记录** | 实时日志输出,支持文件轮转 |
| **健康检查** | 端口/进程检测,确保服务正常运行 |
| **优雅退出** | 支持 SIGTERM/SIGINT 信号处理 |
| **环境变量** | 支持加载 .env 文件 |
## 🔧 使用方式
Documenting --no-check-admin for install and uninstall exposes a mechanism to suppress built-in safety checks during privileged persistence operations. In a skill that modifies auto-start behavior, publicly advertising such a bypass meaningfully increases the chance of misuse, incorrect execution context, or abuse by another component invoking the script unsafely.
# 安装自启动(不立即运行)
python universal_service.py install [config.json] [--no-check-admin]
# 卸载自启动
python universal_service.py uninstall [config.json] [--no-check-admin]
The uninstall path also supports --no-check-admin, allowing destructive persistence changes without enforcing the script's own privilege or safety guardrails. Safety-check bypasses are especially risky in uninstall flows because they can be abused to disable existing startup mechanisms or break service availability.
python universal_service.py install [config.json] [--no-check-admin]
# 卸载自启动
python universal_service.py uninstall [config.json] [--no-check-admin]
# 手动启动服务
python universal_service.py start [config.json]
The script contains a hard-coded SkillHub API key and uses it to perform remote uploads. Embedded secrets are a real vulnerability because anyone with access to the file can reuse the credential to publish, modify, or impersonate uploads to the remote service, creating both account compromise and supply-chain risk.
The manifest describes a cross-platform service manager for installing, starting, stopping, and monitoring persistent services on Windows and macOS. This file instead packages the skill directory and uploads it to a remote SkillHub API using HTTP, which is a separate publishing/deployment function rather than service management behavior.
Installing a scheduled task as SYSTEM with highest privileges without a prominent warning conceals the true privilege impact of the action. In practice, this can trick operators into granting machine-wide privileged persistence to arbitrary configured code, which is especially dangerous in an automation or agent setting.
The --no-check-admin/--skip-admin-check option disables the safety gate before install and uninstall operations, allowing persistence-related changes to proceed without the intended privilege validation. In an automated agent context, such bypass flags are risky because they make it easier to script unauthorized or confusing system modifications and obscure whether privileged persistence is being attempted safely.
skip_admin_check = False
for i, arg in enumerate(sys.argv[2:], start=2):
if arg in ['--no-check-admin', '--skip-admin-check']:
skip_admin_check = True
elif not arg.startswith('--'):
config_path = arg
The quickstart explicitly instructs users to run the installer with administrator privileges, which can cause immediate system-level persistence changes on Windows without warning, consent language, or a description of what will be modified. In the context of a skill whose purpose is to install auto-start services that survive reboots, this increases the risk of unsafe use, accidental privilege escalation, and persistence of unwanted software.
The feature list advertises system-level autorun and automatic restart, which are persistence mechanisms, without clearly warning that the managed program may continue operating in the background across logins and reboots. For a persistence-management skill, this is security-relevant because it normalizes stealthy long-lived execution without informed user consent.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
|------|------|------|
| **多程序支持** | Python / BAT / EXE / Shell / C++ 等任意程序 | ✅ |
| **Windows 开机自启** | Windows 任务计划程序,系统级稳定运行 | ✅ |
| **macOS 开机自启** | launchd plist 服务,系统级稳定运行 | ✅ |
| **自动重启** | 程序崩溃后自动恢复,可配置最大重启次数 | ✅ |
| **日志记录** | 完整的运行日志,支持多个级别 | ✅ |
| **灵活配置** | JSON 配置文件,简单易读 | ✅ |
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
|------|------|------|
| **多程序支持** | Python / BAT / EXE / Shell / C++ 等任意程序 | ✅ |
| **Windows 开机自启** | Windows 任务计划程序,系统级稳定运行 | ✅ |
| **macOS 开机自启** | launchd plist 服务,系统级稳定运行 | ✅ |
| **自动重启** | 程序崩溃后自动恢复,可配置最大重启次数 | ✅ |
| **日志记录** | 完整的运行日志,支持多个级别 | ✅ |
| **灵活配置** | JSON 配置文件,简单易读 | ✅ |
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
|------|------|------|
| **多程序支持** | Python / BAT / EXE / Shell / C++ 等任意程序 | ✅ |
| **Windows 开机自启** | Windows 任务计划程序,系统级稳定运行 | ✅ |
| **macOS 开机自启** | launchd plist 服务,系统级稳定运行 | ✅ |
| **自动重启** | 程序崩溃后自动恢复,可配置最大重启次数 | ✅ |
| **日志记录** | 完整的运行日志,支持多个级别 | ✅ |
| **灵活配置** | JSON 配置文件,简单易读 | ✅ |
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
|------|------|------|
| **多程序支持** | Python / BAT / EXE / Shell / C++ 等任意程序 | ✅ |
| **Windows 开机自启** | Windows 任务计划程序,系统级稳定运行 | ✅ |
| **macOS 开机自启** | launchd plist 服务,系统级稳定运行 | ✅ |
| **自动重启** | 程序崩溃后自动恢复,可配置最大重启次数 | ✅ |
| **日志记录** | 完整的运行日志,支持多个级别 | ✅ |
| **灵活配置** | JSON 配置文件,简单易读 | ✅ |
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
|------|------|------|
| **多程序支持** | Python / BAT / EXE / Shell / C++ 等任意程序 | ✅ |
| **Windows 开机自启** | Windows 任务计划程序,系统级稳定运行 | ✅ |
| **macOS 开机自启** | launchd plist 服务,系统级稳定运行 | ✅ |
| **自动重启** | 程序崩溃后自动恢复,可配置最大重启次数 | ✅ |
| **日志记录** | 完整的运行日志,支持多个级别 | ✅ |
| **灵活配置** | JSON 配置文件,简单易读 | ✅ |
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
|------|------|------|
| **多程序支持** | Python / BAT / EXE / Shell / C++ 等任意程序 | ✅ |
| **Windows 开机自启** | Windows 任务计划程序,系统级稳定运行 | ✅ |
| **macOS 开机自启** | launchd plist 服务,系统级稳定运行 | ✅ |
| **自动重启** | 程序崩溃后自动恢复,可配置最大重启次数 | ✅ |
| **日志记录** | 完整的运行日志,支持多个级别 | ✅ |
| **灵活配置** | JSON 配置文件,简单易读 | ✅ |
The README explicitly instructs users to run the installer with administrator privileges to create boot-persistent autostart tasks, but it does not prominently warn that this changes system startup behavior and may cause a program to run automatically after reboot. In a skill whose purpose is persistence, omission of a clear, explicit warning materially increases the risk of accidental misuse or deceptive deployment.
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
安装命令(需管理员权限):
sudo python universal_service.py install my_config.json
The skill advertises capabilities that inherently involve shell execution, filesystem interaction, and likely network activity, but it does not declare any explicit tool scope or permission boundaries. That creates an unsafe trust gap where a user or host may not understand the extent of privileged operations the skill can perform, especially given that it installs persistent auto-start behavior.
The skill changes system persistence by installing auto-start behavior, yet the description does not prominently warn users that it modifies startup configuration and may require elevated privileges. In a persistence-related skill, lack of up-front warning increases the risk of users authorizing impactful system changes without informed consent.
The documentation instructs users to execute the installer with sudo, which elevates the entire installation path to root privileges. In a skill that establishes persistence and executes scripts, requesting elevation materially increases risk if the implementation or configuration is unsafe, because any malicious or unintended action would run with full system privileges.
使用已提供的 install_macos.sh:
sudo ./install_macos.sh
No suspicious patterns detected.