Back to skill

Security audit

Mac mini — 24/7 agent host, Tailscale SSH, reboot recovery

Security checks for vulnerabilities and agentic risk

Overview

This skill gives clear, purpose-aligned guidance for keeping a dedicated Mac mini reachable remotely, while openly warning about the security trade-offs.

Install only if you are intentionally setting up a dedicated Mac mini for unattended agent hosting. The skill asks you to enable persistent private-network remote access and consider an availability trade-off that can weaken local security, so avoid using it on laptops, shared computers, or machines with personal data. Keep the agent account non-admin, use scoped revocable credentials, and record owner approval for any auto-login/FileVault decision.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Output HandlingUnvalidated Output Injection, Cross-Context Output, Unbounded Output
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (19)

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 55)May include surrounding context.

md
- [ ] **1. Remote desktop as a service, not an app.** Whatever tool you use must be a login item *and* allowed in the background (System Settings → General → Login Items & Extensions), with a permanent unattended password and its privacy grants. A remote-desktop app launched by hand dies with the session — the classic way a Mac becomes unreachable at the login window.
- [ ] **2. Tailscale, formula build** (§Tailscale).
- [ ] **3. Remote Login (sshd)** + your public key in the agent account's `~/.ssh/authorized_keys` (mode 600, dir 700).
- [ ] **4. Power** (§Power), verified in the same line.
- [ ] **5. The login decision** (§Read first): Option A or B, by a human, in System Settings.
- [ ] **6. Agent service** installed as a LaunchAgent of the agent account (see `always-on-agent-ops` for the gateway itself).

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 71)May include surrounding context.

(umask 077; pbpaste > "$HOME/.tskey") brew install tailscale sudo brew services start tailscale sudo tailscale up --auth-key "file:$HOME/.tskey" --hostname=HOSTNAME; rm -f "$HOME/.tskey"; tailscale ip -4

Output: the node's Tailscale IPv4 address

text

Chaining Abuse

High
Category
Tool Misuse
Confidence
82% confidence
Finding

This command chains a privileged enrollment step, secret-file deletion, and status output with ';', so later commands run even if 'sudo tailscale up' fails. That can delete the only copy of the auth key before successful enrollment and obscure failure state, increasing the chance of broken remote access and unsafe recovery actions on an unattended host.

Content

Scanner excerpt · SKILL.md (reported line 71)May include surrounding context.

(umask 077; pbpaste > "$HOME/.tskey") brew install tailscale sudo brew services start tailscale sudo tailscale up --auth-key "file:$HOME/.tskey" --hostname=HOSTNAME; rm -f "$HOME/.tskey"; tailscale ip -4

Output: the node's Tailscale IPv4 address

text

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 47)May include surrounding context.

md
| "can I reach the mac from home?" | §Tailscale — formula, reusable key, key expiry off |
| "the agent is up but can't click anything" | §The walls without MDM — TCC grant |
| "check all the macs" | §Fleet health |
| "sudo pmset worked, didn't it?" | §Power — verify in the same line |

## Bootstrap checklist — order is causal

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 116)May include surrounding context.

md
| "can I reach the mac from home?" | §Tailscale — formula, reusable key, key expiry off |
| "the agent is up but can't click anything" | §The walls without MDM — TCC grant |
| "check all the macs" | §Fleet health |
| "sudo pmset worked, didn't it?" | §Power — verify in the same line |

## Bootstrap checklist — order is causal

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 118)May include surrounding context.

md
| "can I reach the mac from home?" | §Tailscale — formula, reusable key, key expiry off |
| "the agent is up but can't click anything" | §The walls without MDM — TCC grant |
| "check all the macs" | §Fleet health |
| "sudo pmset worked, didn't it?" | §Power — verify in the same line |

## Bootstrap checklist — order is causal

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 201)May include surrounding context.

md
| "can I reach the mac from home?" | §Tailscale — formula, reusable key, key expiry off |
| "the agent is up but can't click anything" | §The walls without MDM — TCC grant |
| "check all the macs" | §Fleet health |
| "sudo pmset worked, didn't it?" | §Power — verify in the same line |

## Bootstrap checklist — order is causal

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 70)May include surrounding context.

bash
(umask 077; pbpaste > "$HOME/.tskey")
brew install tailscale
sudo brew services start tailscale
sudo tailscale up --auth-key "file:$HOME/.tskey" --hostname=HOSTNAME; rm -f "$HOME/.tskey"; tailscale ip -4
# Output: the node's Tailscale IPv4 address

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 71)May include surrounding context.

bash
(umask 077; pbpaste > "$HOME/.tskey")
brew install tailscale
sudo brew services start tailscale
sudo tailscale up --auth-key "file:$HOME/.tskey" --hostname=HOSTNAME; rm -f "$HOME/.tskey"; tailscale ip -4
# Output: the node's Tailscale IPv4 address

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 82)May include surrounding context.

bash
(umask 077; pbpaste > "$HOME/.tskey")
brew install tailscale
sudo brew services start tailscale
sudo tailscale up --auth-key "file:$HOME/.tskey" --hostname=HOSTNAME; rm -f "$HOME/.tskey"; tailscale ip -4
# Output: the node's Tailscale IPv4 address

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 92)May include surrounding context.

bash
(umask 077; pbpaste > "$HOME/.tskey")
brew install tailscale
sudo brew services start tailscale
sudo tailscale up --auth-key "file:$HOME/.tskey" --hostname=HOSTNAME; rm -f "$HOME/.tskey"; tailscale ip -4
# Output: the node's Tailscale IPv4 address

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 93)May include surrounding context.

bash
(umask 077; pbpaste > "$HOME/.tskey")
brew install tailscale
sudo brew services start tailscale
sudo tailscale up --auth-key "file:$HOME/.tskey" --hostname=HOSTNAME; rm -f "$HOME/.tskey"; tailscale ip -4
# Output: the node's Tailscale IPv4 address

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 103)May include surrounding context.

bash
(umask 077; pbpaste > "$HOME/.tskey")
brew install tailscale
sudo brew services start tailscale
sudo tailscale up --auth-key "file:$HOME/.tskey" --hostname=HOSTNAME; rm -f "$HOME/.tskey"; tailscale ip -4
# Output: the node's Tailscale IPv4 address

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 107)May include surrounding context.

bash
(umask 077; pbpaste > "$HOME/.tskey")
brew install tailscale
sudo brew services start tailscale
sudo tailscale up --auth-key "file:$HOME/.tskey" --hostname=HOSTNAME; rm -f "$HOME/.tskey"; tailscale ip -4
# Output: the node's Tailscale IPv4 address

Unbounded Output

Medium
Category
Output Handling
Confidence
60% confidence
Finding

Output size or generation rate is not bounded. Unbounded output enables denial-of-service through resource exhaustion, log flooding, or context-window stuffing.

Content

Scanner excerpt · SKILL.md (reported line 79)May include surrounding context.

md
|---|---|---|
| Formula, not cask | The formula ships the open-source `tailscaled`, which runs **before** any user logs in. The cask is the GUI app: it dies with the session. | A reboot to the login window takes the network down with it — the exact failure you installed Tailscale to survive. |
| Auth key **Reusable** | One key enrols a batch of machines. | A single-use key is consumed by the first Mac; the next ones get a generic `invalid key: API key ... not valid` that never says "already used". |
| **Disable key expiry** per device (admin console → Machines → ⋯) | This click, not the auth key's lifetime, keeps the node on the network. Auth keys only enrol (90 days max) and can be revoked afterwards without cutting anyone. | Node keys expire (default 180 days) and the host silently drops off. |
| Native sshd over Tailscale, **not** `tailscale up --ssh` | Tailscale SSH's default `check` mode re-authenticates in a browser every 12 h. | Every unattended script breaks twice a day. |

`--auth-key file:PATH` keeps the key out of shell history and `ps`. `sudo brew services list` must show `tailscale` started as `root` — listed only under your user means it will not survive logout. The flag is `--auth-key`; `--authkey` is an accepted alias.

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 92)May include surrounding context.

Remote Login

bash
sudo launchctl enable system/com.openssh.sshd
sudo launchctl bootstrap system /System/Library/LaunchDaemons/ssh.plist
nc -z -G 3 127.0.0.1 22; echo "sshd=$?"
# Output: sshd=0

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 118)May include surrounding context.

Remote Login

bash
sudo launchctl enable system/com.openssh.sshd
sudo launchctl bootstrap system /System/Library/LaunchDaemons/ssh.plist
nc -z -G 3 127.0.0.1 22; echo "sshd=$?"
# Output: sshd=0

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 93)May include surrounding context.

bash
sudo launchctl enable system/com.openssh.sshd
sudo launchctl bootstrap system /System/Library/LaunchDaemons/ssh.plist
nc -z -G 3 127.0.0.1 22; echo "sshd=$?"
# Output: sshd=0

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 154)May include surrounding context.

md
| 2 | `ssh -o ConnectTimeout=8 -o BatchMode=yes agent@host-a true` | Remote Login off, or key not in `authorized_keys` | Remote desktop → §Remote Login. |
| 3 | Password prompt, then the connection drops | macOS 26 pre-boot FileVault unlock (Option A after a reboot) | Expected. Reconnect; then step 4 will be red until a human logs in. |
| 4 | `ssh agent@host-a 'stat -f %Su /dev/console'` → `root` | No GUI session: auto-login not set, or FileVault came back after an update | Log in via screen sharing; re-check §Read first. |
| 5 | `ssh agent@host-a 'launchctl print gui/$(id -u)/ai.openclaw.gateway'` fails | Session up, service not loaded | `launchctl kickstart -k gui/$(id -u)/ai.openclaw.gateway`; if absent, reinstall the service (`always-on-agent-ops`). |
| 6 | Agent runs, GUI actions silently do nothing | Privacy grant missing or reset by an update | Human click (§Walls). |
| 7 | Remote desktop shows a black screen / dead mouse | Its own privacy grants were reset | Same: human click on site or via SSH-only triage. |

Static analysis

No suspicious patterns detected.