Back to skill

Security audit

universal-autostart

Security checks for vulnerabilities and agentic risk

Overview

This skill is an auto-start manager, but it installs high-privilege persistent tasks and includes an unrelated publishing script with a hard-coded upload credential.

Install only if you intentionally want a program to run automatically across reboots and you trust the configuration and all files in the package. Review or remove publish_textonly.py, rotate the exposed SkillHub key, avoid SYSTEM/root defaults where possible, and verify that uninstall removes the exact task or plist that was installed.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (5)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
universal_service.py:263
Finding

Mutable service assets can be persisted as a highest-privilege Windows SYSTEM task

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
publish_textonly.py:13
Finding

Hard-coded SkillHub bearer credential can be included in the uploaded package

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
install_macos.sh:8
Finding

macOS wrappers require unnecessary root execution for a user LaunchAgent

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
universal_service.py:297
Finding

Unvalidated service names permit macOS plist path traversal and XML injection

Content
View full analysis
Label {service_name} ProgramArguments {python_exe} {startup_script} RunAtLoad KeepAlive WorkingDirectory {str(script_dir)} StandardOutPath {str(script_dir)}service.log StandardErrorPath {str(script_dir)}error.log ''' with open(plist_path, 'w') as f: f.write(plist_content) ``` The same unvalidated value is used during removal: ```python import getpass username = getpass.getuser() plist_path = Path(f"/Users/{username}/Library/LaunchAgents/{service_name}.plist") subprocess.run(['launchctl', 'unload', '-w', str(plist_path)], capture_output=True) if plist_path.exists(): plist_path.unlink() ``` ### Technical Analysis `service_name` originates from the JSON configuration and is used directly in a filesystem path. There is no restriction to a filename-safe label, no rejection of path separators or `..`, and no resolved-path containment check. A crafted service name can therefore cause the calculated path to escape the intended LaunchAgents directory. The same value and other ...[truncated 1338 chars]
Remediation
View remediation

T06 · System Persistence

Note
Location
uninstall_macos.sh:16
Finding

macOS uninstall targets the default service instead of the configured installed service

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (78)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This is a severe description-behavior mismatch: the skill claims to manage OS auto-start services, but the analysis indicates unrelated behavior including collecting local files, packaging them, and uploading them to a remote API using a hardcoded credential. Hidden file collection and exfiltration under the cover of a persistence-management utility is highly suspicious and could directly lead to data theft and unauthorized publishing actions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This is a severe description-behavior mismatch: the skill claims to manage OS auto-start services, but the analysis indicates unrelated behavior including collecting local files, packaging them, and uploading them to a remote API using a hardcoded credential. Hidden file collection and exfiltration under the cover of a persistence-management utility is highly suspicious and could directly lead to data theft and unauthorized publishing actions.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

The provided Windows installer intentionally passes --no-check-admin to the service-management script after its own wrapper-level privilege check. Bypass flags that disable safety validation are dangerous because they can be reused outside the intended wrapper, weakening defense in depth for operations that modify persistence and system startup behavior.

Content

Scanner excerpt · SKILL.md (reported line 54)May include surrounding context.

md
)

:: 安装服务
python "%~dp0universal_service.py" install "%CONFIG_FILE%" --no-check-admin

if %errorLevel% equ 0 (
    echo [OK] 安装完成!服务将在下次开机自动启动

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 84)May include surrounding context.

md
| **日志记录** | 实时日志输出,支持文件轮转 |
| **健康检查** | 端口/进程检测,确保服务正常运行 |
| **优雅退出** | 支持 SIGTERM/SIGINT 信号处理 |
| **环境变量** | 支持加载 .env 文件 |

## 🔧 使用方式

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 204)May include surrounding context.

md
| **日志记录** | 实时日志输出,支持文件轮转 |
| **健康检查** | 端口/进程检测,确保服务正常运行 |
| **优雅退出** | 支持 SIGTERM/SIGINT 信号处理 |
| **环境变量** | 支持加载 .env 文件 |

## 🔧 使用方式

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 315)May include surrounding context.

md
| **日志记录** | 实时日志输出,支持文件轮转 |
| **健康检查** | 端口/进程检测,确保服务正常运行 |
| **优雅退出** | 支持 SIGTERM/SIGINT 信号处理 |
| **环境变量** | 支持加载 .env 文件 |

## 🔧 使用方式

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Documenting --no-check-admin for install and uninstall exposes a mechanism to suppress built-in safety checks during privileged persistence operations. In a skill that modifies auto-start behavior, publicly advertising such a bypass meaningfully increases the chance of misuse, incorrect execution context, or abuse by another component invoking the script unsafely.

Content

Scanner excerpt · SKILL.md (reported line 92)May include surrounding context.

bash
# 安装自启动(不立即运行)
python universal_service.py install [config.json] [--no-check-admin]

# 卸载自启动
python universal_service.py uninstall [config.json] [--no-check-admin]

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

The uninstall path also supports --no-check-admin, allowing destructive persistence changes without enforcing the script's own privilege or safety guardrails. Safety-check bypasses are especially risky in uninstall flows because they can be abused to disable existing startup mechanisms or break service availability.

Content

Scanner excerpt · SKILL.md (reported line 95)May include surrounding context.

md
python universal_service.py install [config.json] [--no-check-admin]

# 卸载自启动
python universal_service.py uninstall [config.json] [--no-check-admin]

# 手动启动服务
python universal_service.py start [config.json]

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script contains a hard-coded SkillHub API key and uses it to perform remote uploads. Embedded secrets are a real vulnerability because anyone with access to the file can reuse the credential to publish, modify, or impersonate uploads to the remote service, creating both account compromise and supply-chain risk.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest describes a cross-platform service manager for installing, starting, stopping, and monitoring persistent services on Windows and macOS. This file instead packages the skill directory and uploads it to a remote SkillHub API using HTTP, which is a separate publishing/deployment function rather than service management behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Installing a scheduled task as SYSTEM with highest privileges without a prominent warning conceals the true privilege impact of the action. In practice, this can trick operators into granting machine-wide privileged persistence to arbitrary configured code, which is especially dangerous in an automation or agent setting.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

The --no-check-admin/--skip-admin-check option disables the safety gate before install and uninstall operations, allowing persistence-related changes to proceed without the intended privilege validation. In an automated agent context, such bypass flags are risky because they make it easier to script unauthorized or confusing system modifications and obscure whether privileged persistence is being attempted safely.

Content

Scanner excerpt · universal_service.py (reported line 453)May include surrounding context.

python
skip_admin_check = False
        
        for i, arg in enumerate(sys.argv[2:], start=2):
            if arg in ['--no-check-admin', '--skip-admin-check']:
                skip_admin_check = True
            elif not arg.startswith('--'):
                config_path = arg

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The quickstart explicitly instructs users to run the installer with administrator privileges, which can cause immediate system-level persistence changes on Windows without warning, consent language, or a description of what will be modified. In the context of a skill whose purpose is to install auto-start services that survive reboots, this increases the risk of unsafe use, accidental privilege escalation, and persistence of unwanted software.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The feature list advertises system-level autorun and automatic restart, which are persistence mechanisms, without clearly warning that the managed program may continue operating in the background across logins and reboots. For a persistence-management skill, this is security-relevant because it normalizes stealthy long-lived execution without informed user consent.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 37)May include surrounding context.

md
|------|------|------|
| **多程序支持** | Python / BAT / EXE / Shell / C++ 等任意程序 | ✅ |
| **Windows 开机自启** | Windows 任务计划程序,系统级稳定运行 | ✅ |
| **macOS 开机自启** | launchd plist 服务,系统级稳定运行 | ✅ |
| **自动重启** | 程序崩溃后自动恢复,可配置最大重启次数 | ✅ |
| **日志记录** | 完整的运行日志,支持多个级别 | ✅ |
| **灵活配置** | JSON 配置文件,简单易读 | ✅ |

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · universal_service.py (reported line 399)May include surrounding context.

python
|------|------|------|
| **多程序支持** | Python / BAT / EXE / Shell / C++ 等任意程序 | ✅ |
| **Windows 开机自启** | Windows 任务计划程序,系统级稳定运行 | ✅ |
| **macOS 开机自启** | launchd plist 服务,系统级稳定运行 | ✅ |
| **自动重启** | 程序崩溃后自动恢复,可配置最大重启次数 | ✅ |
| **日志记录** | 完整的运行日志,支持多个级别 | ✅ |
| **灵活配置** | JSON 配置文件,简单易读 | ✅ |

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · universal_service.py (reported line 402)May include surrounding context.

python
|------|------|------|
| **多程序支持** | Python / BAT / EXE / Shell / C++ 等任意程序 | ✅ |
| **Windows 开机自启** | Windows 任务计划程序,系统级稳定运行 | ✅ |
| **macOS 开机自启** | launchd plist 服务,系统级稳定运行 | ✅ |
| **自动重启** | 程序崩溃后自动恢复,可配置最大重启次数 | ✅ |
| **日志记录** | 完整的运行日志,支持多个级别 | ✅ |
| **灵活配置** | JSON 配置文件,简单易读 | ✅ |

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · universal_service.py (reported line 405)May include surrounding context.

python
|------|------|------|
| **多程序支持** | Python / BAT / EXE / Shell / C++ 等任意程序 | ✅ |
| **Windows 开机自启** | Windows 任务计划程序,系统级稳定运行 | ✅ |
| **macOS 开机自启** | launchd plist 服务,系统级稳定运行 | ✅ |
| **自动重启** | 程序崩溃后自动恢复,可配置最大重启次数 | ✅ |
| **日志记录** | 完整的运行日志,支持多个级别 | ✅ |
| **灵活配置** | JSON 配置文件,简单易读 | ✅ |

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · universal_service.py (reported line 406)May include surrounding context.

python
|------|------|------|
| **多程序支持** | Python / BAT / EXE / Shell / C++ 等任意程序 | ✅ |
| **Windows 开机自启** | Windows 任务计划程序,系统级稳定运行 | ✅ |
| **macOS 开机自启** | launchd plist 服务,系统级稳定运行 | ✅ |
| **自动重启** | 程序崩溃后自动恢复,可配置最大重启次数 | ✅ |
| **日志记录** | 完整的运行日志,支持多个级别 | ✅ |
| **灵活配置** | JSON 配置文件,简单易读 | ✅ |

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · universal_service.py (reported line 407)May include surrounding context.

python
|------|------|------|
| **多程序支持** | Python / BAT / EXE / Shell / C++ 等任意程序 | ✅ |
| **Windows 开机自启** | Windows 任务计划程序,系统级稳定运行 | ✅ |
| **macOS 开机自启** | launchd plist 服务,系统级稳定运行 | ✅ |
| **自动重启** | 程序崩溃后自动恢复,可配置最大重启次数 | ✅ |
| **日志记录** | 完整的运行日志,支持多个级别 | ✅ |
| **灵活配置** | JSON 配置文件,简单易读 | ✅ |

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README explicitly instructs users to run the installer with administrator privileges to create boot-persistent autostart tasks, but it does not prominently warn that this changes system startup behavior and may cause a program to run automatically after reboot. In a skill whose purpose is persistence, omission of a clear, explicit warning materially increases the risk of accidental misuse or deceptive deployment.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 411)May include surrounding context.

安装命令(需管理员权限):

bash
sudo python universal_service.py install my_config.json

场景 5: Node.js 应用自启动 🟨

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
96% confidence
Finding

The skill advertises capabilities that inherently involve shell execution, filesystem interaction, and likely network activity, but it does not declare any explicit tool scope or permission boundaries. That creates an unsafe trust gap where a user or host may not understand the extent of privileged operations the skill can perform, especially given that it installs persistent auto-start behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill changes system persistence by installing auto-start behavior, yet the description does not prominently warn users that it modifies startup configuration and may require elevated privileges. In a persistence-related skill, lack of up-front warning increases the risk of users authorizing impactful system changes without informed consent.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
82% confidence
Finding

The documentation instructs users to execute the installer with sudo, which elevates the entire installation path to root privileges. In a skill that establishes persistence and executes scripts, requesting elevation materially increases risk if the implementation or configuration is unsafe, because any malicious or unintended action would run with full system privileges.

Content

Scanner excerpt · SKILL.md (reported line 72)May include surrounding context.

使用已提供的 install_macos.sh:

bash
sudo ./install_macos.sh

📋 核心功能

Static analysis

No suspicious patterns detected.