T06 · System Persistence
- Location
setup-service.mjs:29- Finding
Persistent macOS LaunchAgent With Automatic Restart
- Content
View full analysis
Label ${LABEL} ProgramArguments ${NODE_PATH} ${BRIDGE_PATH} WorkingDirectory ${WORK_DIR} RunAtLoad KeepAlive ``` ```javascript const outPath = path.join(HOME, 'Library', 'LaunchAgents', `${LABEL}.plist`); fs.mkdirSync(path.dirname(outPath), { recursive: true }); fs.writeFileSync(outPath, plist); console.log(`✅ Wrote: ${outPath}`); console.log(); console.log('To start the service:'); console.log(` launchctl load ${outPath}`); console.log(); console.log('To stop:'); console.log(` launchctl unload ${outPath}`); ``` The Skill documentation instructs users to activate the generated service: ```bash FEISHU_APP_ID=cli_xxx node setup-service.mjs launchctl load ~/Library/LaunchAgents/com.clawdbot.feishu-bridge.plist ``` ### Technical Analysis The setup script writes a user LaunchAgent into `~/Library/LaunchAgents`. The combination of `RunAtLoad` and `KeepAlive` causes the bridge to start automatically when the LaunchAgent is loaded and to be restarted after it terminates. An always-running process is operationally relevant for a messaging bridge, and the behavior is disclosed rather than concealed. However, persistence is not required for the bridge's basic functionality because it can be run interactively with `node bridge.mjs`. The service therefore exceeds the minimum privileges and ...[truncated 1686 chars]- Remediation
View remediation
