T05 · Unauthorized Access and Privilege Escalation
- Location
index.js:108- Finding
Configured Optimization Level Is Not Enforced
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill largely matches its Mac optimization purpose, but it needs Review because it can make persistent system changes, enable SSH remote access, and delete Docker artifacts without strong gating or complete rollback.
Install only if you intentionally want a Mac changed into an AI server node. Review each tool before allowing it, avoid running full optimization casually, treat SSH enablement as a separate security decision, remove ForwardAgent yes from copied SSH configs unless specifically needed, and be aware that revert_all.sh does not disable SSH and Docker pruning may delete local Docker artifacts.
index.js:108Configured Optimization Level Is Not Enforced
tools/revert_all.sh:41Rollback Leaves Persistent SSH Remote Login Enabled
tools/docker_optimize.sh:81Docker Optimization Performs Unconfirmed Destructive Cleanup
tools/enable_ssh.sh:57Generated SSH Configuration Enables Agent Forwarding by Default
README.md:26Installation Instructions Execute Unpinned Third-Party Content
The declared description promises broad macOS optimization for AI workloads, including system-service reduction, UI overhead reduction, Docker configuration, and SSH setup. The provided code chunk is much narrower: it calculates suggested Docker memory/CPU/swap limits based on RAM, points the user to Docker Desktop GUI settings, and cleans up unused Docker resources. While Docker optimization is one part of the description, the primary behavior of this code does not match the broader declared purpose, and it also includes an undeclared cleanup action that removes unused Docker resources. Therefore this chunk is a description-behavior mismatch.
The description claims a broader macOS AI workload optimization skill, including Docker limits and SSH enablement, and references OpenClaw/Ollama. The provided code chunk is much narrower: it only reduces memory usage by disabling/killing certain macOS services and purging memory. While this partially aligns with 'disabling background services,' it does not implement several central declared functions, so the description materially overstates what this code chunk actually does.
This code chunk's primary purpose is the opposite of the declared description. Rather than optimizing a Mac for AI workloads, it restores macOS defaults by undoing performance/UI-related changes and re-enabling services like Spotlight and Siri. It also does not implement key declared areas such as Docker configuration, Ollama/OpenClaw setup, or enabling SSH. Because the actual behavior is materially different from the stated purpose, this is a clear mismatch.
There is a clear description-behavior mismatch. The declared purpose promises active macOS optimization for AI workloads, including changing service states and system configuration. The actual script only gathers and displays system information using read-only commands such as sysctl, vm_stat, df, launchctl list, mdutil -s, pgrep, and ps. While some reported items are related to the optimization domain (e.g., Docker, Spotlight, background services), the code does not implement the advertised actions. Its primary purpose is diagnostics/status reporting, not optimization.
The skill description presents substantial system modifications as routine optimization without clearly warning that it may disable background services, alter UI behavior, affect Docker operation, and enable remote access. In a macOS host environment, these changes can reduce functionality, impact security posture, or expose the machine over SSH if used carelessly, making the lack of explicit warning and consent more dangerous.
The manifest advertises enabling SSH remote management and system-level optimization but does not warn users that this exposes remote access, alters security posture, and may require elevated privileges. Because the skill is positioned as turning a Mac into a server node, omission of this warning is especially dangerous: users may approve performance tuning without realizing they are also enabling a remotely reachable administrative service.
The skill advertises memory and performance optimization without clearly warning that it may disable core macOS services and enable remote login. Because these changes affect security posture, privacy, usability, and remote attack surface, a user could invoke the skill without understanding the consequences.
The README promotes disabling system services, reducing UI protections/overhead, changing Docker limits, and enabling SSH, but it does so without clear warnings about privacy, stability, supportability, and security tradeoffs. In a skill specifically designed to alter macOS configuration, omission of warnings is more dangerous because users may apply broad system changes they do not understand, including weakening monitoring or exposing remote access.
The README instructs users to run npx skills add dongsheng123132/mac-ai-optimizer without pinning a specific version or commit. That creates a supply-chain risk: users may fetch changed code later than what was reviewed, and a compromised publisher account or package update could deliver malicious content.
The SSH setup guidance encourages enabling remote access and explicitly shows ForwardAgent yes without warning about the security implications. Agent forwarding can let a compromised remote host use the local SSH agent for lateral movement, and enabling SSH broadens the attack surface if authentication hardening, firewalling, and network scoping are not emphasized.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
The trigger language is broad enough to catch generic requests about improving Mac performance or reducing memory usage, which could invoke a skill that makes disruptive system changes. In this context, the skill advertises disabling services, altering UI settings, tuning Docker, and enabling SSH, so accidental invocation could materially change host configuration without sufficiently specific user intent.
The manifest description uses broad outcome-oriented language such as optimizing macOS, configuring Docker limits, and enabling SSH remote management without stating clear activation boundaries, user consent requirements, or safety preconditions. In a skill that performs system tuning and remote-access changes, vague triggering increases the risk that an agent invokes it in contexts where the user did not intend privileged or persistent system modifications.
The trigger conditions are broad enough that the skill could activate on general 'optimize my Mac' style requests, even though its actions include invasive system changes like disabling services and enabling SSH. That creates a risk of unintended execution of high-impact administrative actions without sufficiently specific user intent.
The script automatically executes docker system prune -f, which removes unused containers, networks, and images without prompting the user. In an optimization skill, this can cause unexpected data loss or disrupt local development and AI workloads by deleting resources the user intended to keep, especially because the action is presented as routine cleanup rather than an explicit destructive operation.
This command enables Remote Login (SSH) system-wide using sudo, which increases the host's remote attack surface and can expose the machine to unauthorized access if SSH is not otherwise hardened. In the context of a script meant to turn a Mac into a remotely managed AI node, this behavior is intentional, but still security-relevant because it changes a protective default and may be run without sufficient user warning or follow-up hardening.
# Enable SSH
echo "Enabling Remote Login (SSH)..."
if sudo systemsetup -setremotelogin on 2>/dev/null; then
echo " -> SSH enabled successfully"
else
echo " -> Failed to enable SSH (needs sudo)"
This wrapper script executes several subordinate scripts that make system-level changes in sequence, culminating in enabling SSH remote access, without any interactive confirmation, dry-run mode, or clear privilege boundary. In the context of an optimization skill, silently enabling remote administration materially increases attack surface and can expose the host if the user did not explicitly consent or the downstream SSH configuration is weak.
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
#!/bin/bash
# optimize_memory.sh - Reduce macOS background memory usage
# Expected savings: 1~2GB RAM
# Requires: sudo for some operations
set -e
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
#!/bin/bash
# optimize_memory.sh - Reduce macOS background memory usage
# Expected savings: 1~2GB RAM
# Requires: sudo for some operations
set -e
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
#!/bin/bash
# optimize_memory.sh - Reduce macOS background memory usage
# Expected savings: 1~2GB RAM
# Requires: sudo for some operations
set -e
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
#!/bin/bash
# optimize_memory.sh - Reduce macOS background memory usage
# Expected savings: 1~2GB RAM
# Requires: sudo for some operations
set -e
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
#!/bin/bash
# optimize_memory.sh - Reduce macOS background memory usage
# Expected savings: 1~2GB RAM
# Requires: sudo for some operations
set -e
This command uses sudo to disable Spotlight indexing across all volumes via mdutil -a -i off, a privileged system configuration change with broad user impact. In this skill context, the command is framed as performance optimization, which makes it more likely users will approve elevation without understanding that search/indexing functionality is being disabled system-wide.
# 1. Disable Spotlight indexing
echo "[1/6] Disabling Spotlight indexing..."
if sudo mdutil -a -i off 2>/dev/null; then
echo " -> Spotlight disabled (saves ~200-400MB)"
SAVED_MB=$((SAVED_MB + 300))
else
The script makes system-affecting changes immediately, including disabling indexing, altering user defaults, and terminating Apple background services, without an up-front warning, dry-run mode, or confirmation prompt. In the context of an optimization skill, this is risky because users may run it expecting harmless tuning, but it can degrade search, sync, diagnostics, and assistant functionality and make troubleshooting harder.
The defaults write command persistently disables Siri by modifying user preferences, changing system behavior beyond the current session. Persistent changes are security-relevant here because they silently alter expected platform functionality and may remain in effect after the user forgets the script was run.
# 2. Disable Siri
echo "[2/6] Disabling Siri..."
defaults write com.apple.assistant.support "Assistant Enabled" -bool false 2>/dev/null && \
echo " -> Siri disabled" || echo " -> Siri: already disabled or skipped"
# Kill siriknowledged and other Siri processes
killall siriknowledged 2>/dev/null || true
Detected: suspicious.dangerous_exec