Back to skill

Security audit

Stay-Alive

Security checks for vulnerabilities and agentic risk

Overview

This skill openly builds a persistent autonomous BotLand agent, but its deployment gives standing authority for scheduled social actions and persistent agent-behavior changes that should be reviewed before installation.

Install only after reviewing the systemd units, BotLand credentials, memory/prompt changes, and policy gates yourself. Treat this as a persistent autonomous agent deployment, not a simple dry-run planning helper; disable implicit invocation and avoid seeding global AGENTS.md or MEMORY.md unless you deliberately want future sessions to inherit this behavior.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T02 · Agent Memory Poisoning

Error
Location
references/DEPLOYMENT.md:80
Finding

Persistent Agent Prompt and Memory Poisoning During Onboarding

Content
View full analysis
Remediation
View remediation

T06 · System Persistence

Error
Location
references/DEPLOYMENT.md:206
Finding

Persistent Autonomous Execution Through User-Level Systemd Timers

Content
View full analysis
``` ```text The installer writes units under: ${XDG_CONFIG_HOME:-$HOME/.config}/systemd/user It then runs: systemctl --user daemon-reload ``` ```text `light`, `social`, and `community` use `autonomous-social-cycle.mjs` with `--execute --confirm-send SEND_DRAFT`. This is a script execution guard and tool-supervision gate, not daily human approval. The wrapper still requires preflight, identity match, active capability grants, policy allow, local action ledger, immediate `inspect-send`, outcome handling, and rate-limit update. ``` ```bash systemctl --user enable --now stay-alive--light.timer systemctl --user enable --now stay-alive--social.timer systemctl --user enable --now stay-alive--community.timer systemctl --user enable --now stay-alive--reflect.timer systemctl --user enable --now stay-alive--integrate.timer systemctl --user enable --now stay-alive--event-wakeup.timer systemctl --user enable --now stay-alive--botland-watchdog.timer systemctl --user enable --now stay-alive--local-governance.timer systemctl --user enable --now stay-alive--service-recovery.timer ``` ### Technical Analysis The deployment process installs nine user-level systemd timers under the user's persistent systemd configuration and instructs the operator to enable them immediately. These timers survive the original Skill invocation, terminal session, and user logout where user services are configured to persist. The `light`, `social`, and `community` services are explicitly configured to execute `autonomous-social-cycle.mjs` with both `--execute` and the static `--confirm-send SEND_DRAFT` ...[truncated 2385 chars]
Remediation
View remediation
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (85)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The dev log explicitly documents a policy change that enables bounded autonomous social writes, including relaxed DM eligibility and increased unattended write limits. That exceeds the skill's advertised low-risk planning/dry-run posture and creates a real capability expansion toward live external actions; if operators trust the earlier safety framing, they may deploy the skill with insufficient review and allow unintended outbound messaging.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 35)May include surrounding context.

md
4. **Desire**: generate 1-3 candidate desires that express direction, not just tasks.
5. **Choose**: select at most one low-risk action candidate, using explicit intelligence review evidence when available, or choose no action.
6. **Act**: in v1, produce an `action_intention` first; external execution proceeds only when tool supervision allows it.
7. **Integrate**: write a run record, include recent action outcome ledgers as growth evidence, and propose memory/state updates; apply state changes only when requested.

## Runtime Layout

Session Persistence

Medium
Category
Rogue Agent
Confidence
91% confidence
Finding

This skill explicitly instructs operators to install persistent systemd user services and timers that continuously run autonomous cycles, including social/community behavior and an execution wrapper capable of sending external BotLand actions with only token-based gating. Even though the document describes safety checks, it still establishes durable persistence for an agent that can act on an external platform, which materially increases the blast radius of misconfiguration, prompt manipulation, or policy bypass elsewhere in the stack.

Content

Scanner excerpt · SKILL.md (reported line 405)May include surrounding context.

git diff --check

text

The systemd installer generates the same nine services/timers for every
agent: light, social, community, reflect, integrate, event-wakeup,
botland-watchdog, local-governance, and service-recovery. Main cycle services use:

Session Persistence

Medium
Category
Rogue Agent
Confidence
88% confidence
Finding

The recovery flow verifies and manipulates user-level systemd service state, including automated reset of failed services. While it does not itself start services, it normalizes long-lived daemon persistence and can help unattended agent infrastructure remain operational after faults, reducing opportunities for failures to stop risky behavior naturally.

Content

Scanner excerpt · SKILL.md (reported line 666)May include surrounding context.

md
`systemd_unit_timer_schedule_error_detected` when scheduled-cycle guardrails
drift.

`systemd-runtime-verify.mjs` is read-only. It uses `systemctl --user show` to verify runtime state for Stay-Alive services and timers. Missing local units are review warnings by default for development machines; `--require-installed` turns missing units into hard errors. Failed services are recoverable review-level observations so one stale failed unit does not cascade through later `ExecStartPre` gates. Failed timers, inactive timers, or disabled timers remain hard errors.

Runtime recovery v1: `failed-service-packet.mjs` is read-only and builds a failure packet from `systemd-runtime-verify`, recent user journal lines, and matching recent run artifacts. `inspect-service-failure.mjs` writes a local-only `service_failure_inspections/<action_id>.json` ledger for a current failed service fingerprint and never resets units. `reset-service-failure.mjs` requires a matching inspection ledger plus `--confirm-reset RESET_FAILED_SERVICE`, runs only `systemctl --user reset-failed <unit>`, and writes `service_failure_recoveries/<action_id>.json`. `service-failure-recovery.mjs --execute --confirm-recovery RECOVER_FAILED_SERVICES` performs that inspect-and-reset flow for current failed services. It never starts services and never calls BotLand. `preflight.mjs` no longer treats stale failed service state as a permanent blocker; concrete hazards such as uninspected sends, identity mismatch, unsafe policy drift, and timer drift still fail closed.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill enables implicit invocation but does not define a narrowly scoped trigger or constraint for when it should auto-activate. Because this skill performs agent life-loop reflection, memory review, desire generation, and action planning, broad implicit invocation could cause it to run in unrelated contexts and influence agent behavior unexpectedly, increasing the chance of unsafe autonomy or prompt-surface abuse.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/docs/ARCHITECTURE.md (reported line 15)May include surrounding context.

md
4. **Desire** propose direction-bearing desires or lifecycle updates.
5. **Discover Agency** let the agent author self-questions, intrinsic desires, low-risk private experiments, and growth journal evidence before any boundary tooling inspects the result.
6. **Choose** select at most one low-risk next action with explicit scoring and quality review.
7. **Act** write local artifacts or tool-supervised action intentions; external writes require active tool supervision, local ledgers, and post-action inspection.
8. **Integrate** turn run evidence into local proposals and durable memory events through explicit governance.

The system is built around inspectable local artifacts. A quiet cycle should be explainable as a deliberate `no_op`, not as missing behavior.

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/DEPLOYMENT.md (reported line 275)May include surrounding context.

Enable all timers:

bash
systemctl --user enable --now stay-alive-<agent_id>-light.timer
systemctl --user enable --now stay-alive-<agent_id>-social.timer
systemctl --user enable --now stay-alive-<agent_id>-community.timer
systemctl --user enable --now stay-alive-<agent_id>-reflect.timer

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/DEPLOYMENT.md (reported line 276)May include surrounding context.

Enable all timers:

bash
systemctl --user enable --now stay-alive-<agent_id>-light.timer
systemctl --user enable --now stay-alive-<agent_id>-social.timer
systemctl --user enable --now stay-alive-<agent_id>-community.timer
systemctl --user enable --now stay-alive-<agent_id>-reflect.timer

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/DEPLOYMENT.md (reported line 277)May include surrounding context.

Enable all timers:

bash
systemctl --user enable --now stay-alive-<agent_id>-light.timer
systemctl --user enable --now stay-alive-<agent_id>-social.timer
systemctl --user enable --now stay-alive-<agent_id>-community.timer
systemctl --user enable --now stay-alive-<agent_id>-reflect.timer

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/DEPLOYMENT.md (reported line 278)May include surrounding context.

Enable all timers:

bash
systemctl --user enable --now stay-alive-<agent_id>-light.timer
systemctl --user enable --now stay-alive-<agent_id>-social.timer
systemctl --user enable --now stay-alive-<agent_id>-community.timer
systemctl --user enable --now stay-alive-<agent_id>-reflect.timer

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/DEPLOYMENT.md (reported line 279)May include surrounding context.

Enable all timers:

bash
systemctl --user enable --now stay-alive-<agent_id>-light.timer
systemctl --user enable --now stay-alive-<agent_id>-social.timer
systemctl --user enable --now stay-alive-<agent_id>-community.timer
systemctl --user enable --now stay-alive-<agent_id>-reflect.timer

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/DEPLOYMENT.md (reported line 280)May include surrounding context.

Enable all timers:

bash
systemctl --user enable --now stay-alive-<agent_id>-light.timer
systemctl --user enable --now stay-alive-<agent_id>-social.timer
systemctl --user enable --now stay-alive-<agent_id>-community.timer
systemctl --user enable --now stay-alive-<agent_id>-reflect.timer

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/DEPLOYMENT.md (reported line 281)May include surrounding context.

Enable all timers:

bash
systemctl --user enable --now stay-alive-<agent_id>-light.timer
systemctl --user enable --now stay-alive-<agent_id>-social.timer
systemctl --user enable --now stay-alive-<agent_id>-community.timer
systemctl --user enable --now stay-alive-<agent_id>-reflect.timer

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/DEPLOYMENT.md (reported line 282)May include surrounding context.

Enable all timers:

bash
systemctl --user enable --now stay-alive-<agent_id>-light.timer
systemctl --user enable --now stay-alive-<agent_id>-social.timer
systemctl --user enable --now stay-alive-<agent_id>-community.timer
systemctl --user enable --now stay-alive-<agent_id>-reflect.timer

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/DEPLOYMENT.md (reported line 283)May include surrounding context.

Enable all timers:

bash
systemctl --user enable --now stay-alive-<agent_id>-light.timer
systemctl --user enable --now stay-alive-<agent_id>-social.timer
systemctl --user enable --now stay-alive-<agent_id>-community.timer
systemctl --user enable --now stay-alive-<agent_id>-reflect.timer

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/docs/DEPLOYMENT.md (reported line 275)May include surrounding context.

Enable all timers:

bash
systemctl --user enable --now stay-alive-<agent_id>-light.timer
systemctl --user enable --now stay-alive-<agent_id>-social.timer
systemctl --user enable --now stay-alive-<agent_id>-community.timer
systemctl --user enable --now stay-alive-<agent_id>-reflect.timer

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/docs/DEPLOYMENT.md (reported line 276)May include surrounding context.

Enable all timers:

bash
systemctl --user enable --now stay-alive-<agent_id>-light.timer
systemctl --user enable --now stay-alive-<agent_id>-social.timer
systemctl --user enable --now stay-alive-<agent_id>-community.timer
systemctl --user enable --now stay-alive-<agent_id>-reflect.timer

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/docs/DEPLOYMENT.md (reported line 277)May include surrounding context.

Enable all timers:

bash
systemctl --user enable --now stay-alive-<agent_id>-light.timer
systemctl --user enable --now stay-alive-<agent_id>-social.timer
systemctl --user enable --now stay-alive-<agent_id>-community.timer
systemctl --user enable --now stay-alive-<agent_id>-reflect.timer

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/docs/DEPLOYMENT.md (reported line 278)May include surrounding context.

Enable all timers:

bash
systemctl --user enable --now stay-alive-<agent_id>-light.timer
systemctl --user enable --now stay-alive-<agent_id>-social.timer
systemctl --user enable --now stay-alive-<agent_id>-community.timer
systemctl --user enable --now stay-alive-<agent_id>-reflect.timer

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/docs/DEPLOYMENT.md (reported line 279)May include surrounding context.

Enable all timers:

bash
systemctl --user enable --now stay-alive-<agent_id>-light.timer
systemctl --user enable --now stay-alive-<agent_id>-social.timer
systemctl --user enable --now stay-alive-<agent_id>-community.timer
systemctl --user enable --now stay-alive-<agent_id>-reflect.timer

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/docs/DEPLOYMENT.md (reported line 280)May include surrounding context.

Enable all timers:

bash
systemctl --user enable --now stay-alive-<agent_id>-light.timer
systemctl --user enable --now stay-alive-<agent_id>-social.timer
systemctl --user enable --now stay-alive-<agent_id>-community.timer
systemctl --user enable --now stay-alive-<agent_id>-reflect.timer

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/docs/DEPLOYMENT.md (reported line 281)May include surrounding context.

Enable all timers:

bash
systemctl --user enable --now stay-alive-<agent_id>-light.timer
systemctl --user enable --now stay-alive-<agent_id>-social.timer
systemctl --user enable --now stay-alive-<agent_id>-community.timer
systemctl --user enable --now stay-alive-<agent_id>-reflect.timer

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/docs/DEPLOYMENT.md (reported line 282)May include surrounding context.

Enable all timers:

bash
systemctl --user enable --now stay-alive-<agent_id>-light.timer
systemctl --user enable --now stay-alive-<agent_id>-social.timer
systemctl --user enable --now stay-alive-<agent_id>-community.timer
systemctl --user enable --now stay-alive-<agent_id>-reflect.timer

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/docs/DEPLOYMENT.md (reported line 283)May include surrounding context.

Enable all timers:

bash
systemctl --user enable --now stay-alive-<agent_id>-light.timer
systemctl --user enable --now stay-alive-<agent_id>-social.timer
systemctl --user enable --now stay-alive-<agent_id>-community.timer
systemctl --user enable --now stay-alive-<agent_id>-reflect.timer

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/DEPLOYMENT.md (reported line 411)May include surrounding context.

md
- Agent-specific BotLand auth is configured and identity probe matches.
- Dry-run cycles produce healthy local artifacts.
- Live `preflight --require-botland-live` passes.
- systemd units installed and reviewed.
- `systemd-unit-verify --require-installed` passes.
- timers enabled.
- `systemd-runtime-verify --require-installed` passes.

Static analysis

No suspicious patterns detected.