Back to skill

Security audit

Mac AI Optimizer

Security checks for vulnerabilities and agentic risk

Overview

The skill largely matches its Mac optimization purpose, but it needs Review because it can make persistent system changes, enable SSH remote access, and delete Docker artifacts without strong gating or complete rollback.

Install only if you intentionally want a Mac changed into an AI server node. Review each tool before allowing it, avoid running full optimization casually, treat SSH enablement as a separate security decision, remove ForwardAgent yes from copied SSH configs unless specifically needed, and be aware that revert_all.sh does not disable SSH and Docker pruning may delete local Docker artifacts.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Findings (5)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
index.js:108
Finding

Configured Optimization Level Is Not Enforced

Content
View full analysis
Remediation
View remediation

T06 · System Persistence

Error
Location
tools/revert_all.sh:41
Finding

Rollback Leaves Persistent SSH Remote Login Enabled

Content
View full analysis
SSH was not disabled (you may want to keep it)" echo " -> To disable: sudo systemsetup -setremotelogin off" echo "" echo "==============================" echo " All optimizations reverted" echo " Restart your Mac for full effect" echo "==============================" ``` The README additionally describes the feature as a “One-click revert to defaults” and states that running `revert_all.sh` or restarting the Mac restores the system. ### Technical Analysis `full_optimize.sh` enables macOS Remote Login through `sudo systemsetup -setremotelogin on`. That setting survives the Skill invocation and system reboots. The rollback script deliberately does not disable Remote Login, but still prints `All optimizations reverted`. Restarting the Mac also does not reverse the setting. This creates a dangerous mismatch between the claimed rollback state and the actual network exposure. The script also does not record whether SSH was enabled before optimization. A secure rollback must restore the original state rather than always enabling or disabling the service. ### Attack Path 1. The user or Agent runs `mac_full_optimize`. 2. `enable_ssh.sh` enables macOS Remote Login. 3. The SSH service becomes reachable on applicable network interfaces under the host's firewall and network configuration. 4. The user later runs `mac_revert_optimizations`, expecting all changes to be undone. 5. The script preserves Remote Login while reporting that all optimizations were reverted. 6. SSH remains available across future sessions and reboots. 7. An attacker with network access can continue attempting authentication against permitted local accounts. ### Impact Assessment The affected Mac can remain exposed to remote auth ...[truncated 577 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
tools/docker_optimize.sh:81
Finding

Docker Optimization Performs Unconfirmed Destructive Cleanup

Content
View full analysis
/dev/null; then echo " -> Unused containers, networks, and images removed" else echo " -> Docker not running or prune failed" fi ``` ### Technical Analysis The tool is presented primarily as a Docker Desktop resource-limit optimizer. However, it unconditionally executes: ```bash docker system prune -f ``` The `-f` option suppresses Docker's interactive confirmation. This can delete all stopped containers, unused networks, dangling images, and eligible build cache. These artifacts may be intentionally retained for rollback, incident analysis, offline development, or deployment recovery. The script does not actually modify Docker's CPU, memory, or swap limits. It only prints recommended GUI settings. Therefore, the principal automatic mutation performed by the purported optimizer is the destructive cleanup operation. ### Attack Path 1. A user asks the Agent to optimize Docker resource limits. 2. The Agent invokes `mac_docker_optimize`, or the operation runs through `mac_full_optimize`. 3. The script calculates and prints recommended resource values but does not apply them. 4. It automatically invokes `docker system prune -f`. 5. Docker removes eligible stopped containers, networks, images, and build cache without user review. 6. Subsequent builds, rollback procedures, or stopped workloads may no longer have the expected local artifacts. ### Impact Assessment The command runs with the Docker privileges of the current user. In environments where membership in the Docker control group or Docker Desktop access is highly privileged, it can alter resources across all projects managed by that Docker daemon. Potential effects include: - Loss of st ...[truncated 408 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
tools/enable_ssh.sh:57
Finding

Generated SSH Configuration Enables Agent Forwarding by Default

Content
View full analysis
/dev/null | grep "inet " | grep -v "127.0.0.1" | awk '{print $2}' | head -1)" echo " User ${USERNAME}" echo " ForwardAgent yes" ``` The same `ForwardAgent yes` recommendation appears in the README's cluster configuration examples. ### Technical Analysis SSH agent forwarding exposes an agent socket to the remote session. Although the private key itself is not copied to the destination, a process with sufficient access on the destination can request signatures from the forwarded agent while the connection is active. Remote management of an AI node does not require agent forwarding. Enabling it in the default generated configuration unnecessarily extends the authentication authority available to the remote host. This is particularly risky for compute nodes that execute containers, crawlers, third-party models, plugins, or other less-trusted workloads. ### Attack Path 1. The user runs `enable_ssh.sh`. 2. The script recommends an SSH host entry containing `ForwardAgent yes`. 3. The user copies the configuration to the control machine. 4. The user connects while keys are loaded into the local SSH agent. 5. A malicious process or attacker with suitable access on the AI node reaches the forwarded agent socket. 6. While the session is active, the attacker requests authentication signatures through that socket. 7. The forwarded identity may be used to authenticate to other systems that trust the user's key. ### Impact Assessment The affected authority is limited to keys currently available through the forwarded agent and the constraints imposed on those keys. The remote host does not directly ...[truncated 327 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
README.md:26
Finding

Installation Instructions Execute Unpinned Third-Party Content

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (39)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description promises broad macOS optimization for AI workloads, including system-service reduction, UI overhead reduction, Docker configuration, and SSH setup. The provided code chunk is much narrower: it calculates suggested Docker memory/CPU/swap limits based on RAM, points the user to Docker Desktop GUI settings, and cleans up unused Docker resources. While Docker optimization is one part of the description, the primary behavior of this code does not match the broader declared purpose, and it also includes an undeclared cleanup action that removes unused Docker resources. Therefore this chunk is a description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The description claims a broader macOS AI workload optimization skill, including Docker limits and SSH enablement, and references OpenClaw/Ollama. The provided code chunk is much narrower: it only reduces memory usage by disabling/killing certain macOS services and purging memory. While this partially aligns with 'disabling background services,' it does not implement several central declared functions, so the description materially overstates what this code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This code chunk's primary purpose is the opposite of the declared description. Rather than optimizing a Mac for AI workloads, it restores macOS defaults by undoing performance/UI-related changes and re-enabling services like Spotlight and Siri. It also does not implement key declared areas such as Docker configuration, Ollama/OpenClaw setup, or enabling SSH. Because the actual behavior is materially different from the stated purpose, this is a clear mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

There is a clear description-behavior mismatch. The declared purpose promises active macOS optimization for AI workloads, including changing service states and system configuration. The actual script only gathers and displays system information using read-only commands such as sysctl, vm_stat, df, launchctl list, mdutil -s, pgrep, and ps. While some reported items are related to the optimization domain (e.g., Docker, Spotlight, background services), the code does not implement the advertised actions. Its primary purpose is diagnostics/status reporting, not optimization.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description presents substantial system modifications as routine optimization without clearly warning that it may disable background services, alter UI behavior, affect Docker operation, and enable remote access. In a macOS host environment, these changes can reduce functionality, impact security posture, or expose the machine over SSH if used carelessly, making the lack of explicit warning and consent more dangerous.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest advertises enabling SSH remote management and system-level optimization but does not warn users that this exposes remote access, alters security posture, and may require elevated privileges. Because the skill is positioned as turning a Mac into a server node, omission of this warning is especially dangerous: users may approve performance tuning without realizing they are also enabling a remotely reachable administrative service.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill advertises memory and performance optimization without clearly warning that it may disable core macOS services and enable remote login. Because these changes affect security posture, privacy, usability, and remote attack surface, a user could invoke the skill without understanding the consequences.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README promotes disabling system services, reducing UI protections/overhead, changing Docker limits, and enabling SSH, but it does so without clear warnings about privacy, stability, supportability, and security tradeoffs. In a skill specifically designed to alter macOS configuration, omission of warnings is more dangerous because users may apply broad system changes they do not understand, including weakening monitoring or exposing remote access.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
83% confidence
Finding

The README instructs users to run npx skills add dongsheng123132/mac-ai-optimizer without pinning a specific version or commit. That creates a supply-chain risk: users may fetch changed code later than what was reviewed, and a compromised publisher account or package update could deliver malicious content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The SSH setup guidance encourages enabling remote access and explicitly shows ForwardAgent yes without warning about the security implications. Agent forwarding can let a compromised remote host use the local SSH agent for lateral movement, and enabling SSH broadens the attack surface if authentication hardening, firewalling, and network scoping are not emphasized.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger language is broad enough to catch generic requests about improving Mac performance or reducing memory usage, which could invoke a skill that makes disruptive system changes. In this context, the skill advertises disabling services, altering UI settings, tuning Docker, and enabling SSH, so accidental invocation could materially change host configuration without sufficiently specific user intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest description uses broad outcome-oriented language such as optimizing macOS, configuring Docker limits, and enabling SSH remote management without stating clear activation boundaries, user consent requirements, or safety preconditions. In a skill that performs system tuning and remote-access changes, vague triggering increases the risk that an agent invokes it in contexts where the user did not intend privileged or persistent system modifications.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger conditions are broad enough that the skill could activate on general 'optimize my Mac' style requests, even though its actions include invasive system changes like disabling services and enabling SSH. That creates a risk of unintended execution of high-impact administrative actions without sufficiently specific user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script automatically executes docker system prune -f, which removes unused containers, networks, and images without prompting the user. In an optimization skill, this can cause unexpected data loss or disrupt local development and AI workloads by deleting resources the user intended to keep, especially because the action is presented as routine cleanup rather than an explicit destructive operation.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
88% confidence
Finding

This command enables Remote Login (SSH) system-wide using sudo, which increases the host's remote attack surface and can expose the machine to unauthorized access if SSH is not otherwise hardened. In the context of a script meant to turn a Mac into a remotely managed AI node, this behavior is intentional, but still security-relevant because it changes a protective default and may be run without sufficient user warning or follow-up hardening.

Content

Scanner excerpt · tools/enable_ssh.sh (reported line 20)May include surrounding context.

sh
# Enable SSH
echo "Enabling Remote Login (SSH)..."
if sudo systemsetup -setremotelogin on 2>/dev/null; then
    echo "  -> SSH enabled successfully"
else
    echo "  -> Failed to enable SSH (needs sudo)"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This wrapper script executes several subordinate scripts that make system-level changes in sequence, culminating in enabling SSH remote access, without any interactive confirmation, dry-run mode, or clear privilege boundary. In the context of an optimization skill, silently enabling remote administration materially increases attack surface and can expose the host if the user did not explicitly consent or the downstream SSH configuration is weak.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · index.js (reported line 47)May include surrounding context.

js
#!/bin/bash
# optimize_memory.sh - Reduce macOS background memory usage
# Expected savings: 1~2GB RAM
# Requires: sudo for some operations

set -e

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · tools/enable_ssh.sh (reported line 14)May include surrounding context.

sh
#!/bin/bash
# optimize_memory.sh - Reduce macOS background memory usage
# Expected savings: 1~2GB RAM
# Requires: sudo for some operations

set -e

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · tools/optimize_memory.sh (reported line 4)May include surrounding context.

sh
#!/bin/bash
# optimize_memory.sh - Reduce macOS background memory usage
# Expected savings: 1~2GB RAM
# Requires: sudo for some operations

set -e

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · tools/revert_all.sh (reported line 12)May include surrounding context.

sh
#!/bin/bash
# optimize_memory.sh - Reduce macOS background memory usage
# Expected savings: 1~2GB RAM
# Requires: sudo for some operations

set -e

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · tools/revert_all.sh (reported line 44)May include surrounding context.

sh
#!/bin/bash
# optimize_memory.sh - Reduce macOS background memory usage
# Expected savings: 1~2GB RAM
# Requires: sudo for some operations

set -e

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
93% confidence
Finding

This command uses sudo to disable Spotlight indexing across all volumes via mdutil -a -i off, a privileged system configuration change with broad user impact. In this skill context, the command is framed as performance optimization, which makes it more likely users will approve elevation without understanding that search/indexing functionality is being disabled system-wide.

Content

Scanner excerpt · tools/optimize_memory.sh (reported line 17)May include surrounding context.

sh
# 1. Disable Spotlight indexing
echo "[1/6] Disabling Spotlight indexing..."
if sudo mdutil -a -i off 2>/dev/null; then
    echo "  -> Spotlight disabled (saves ~200-400MB)"
    SAVED_MB=$((SAVED_MB + 300))
else

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script makes system-affecting changes immediately, including disabling indexing, altering user defaults, and terminating Apple background services, without an up-front warning, dry-run mode, or confirmation prompt. In the context of an optimization skill, this is risky because users may run it expecting harmless tuning, but it can degrade search, sync, diagnostics, and assistant functionality and make troubleshooting harder.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

The defaults write command persistently disables Siri by modifying user preferences, changing system behavior beyond the current session. Persistent changes are security-relevant here because they silently alter expected platform functionality and may remain in effect after the user forgets the script was run.

Content

Scanner excerpt · tools/optimize_memory.sh (reported line 26)May include surrounding context.

sh
# 2. Disable Siri
echo "[2/6] Disabling Siri..."
defaults write com.apple.assistant.support "Assistant Enabled" -bool false 2>/dev/null && \
    echo "  -> Siri disabled" || echo "  -> Siri: already disabled or skipped"
# Kill siriknowledged and other Siri processes
killall siriknowledged 2>/dev/null || true

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
index.js:14