Back to skill

Security audit

choco

Security checks for vulnerabilities and agentic risk

Overview

This Chocolatey troubleshooting skill is coherent, but it needs Review because it recommends broad administrator-level package and Windows service changes without strong confirmation, rollback, or verification boundaries.

Install only if you are comfortable with an agent helping administer Chocolatey and Windows services. Before running its suggested commands, review every package and service name, avoid `choco upgrade all -y` unless you intend broad system changes, verify any downloaded shawl binary, export or record service configuration before removal, and do not place a real Windows password in a saved script.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (23)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The implemented code matches part of the description well: it supports diagnose, update-path, and post-upgrade behavior for Chocolatey/NSSM service path issues after upgrades. However, the declared purpose materially overstates the skill by claiming NSSM→shawl migration and metadata repair/resync capabilities related to UniGetUI/choco metadata failures. None of that behavior exists in this code chunk. There are no undeclared suspicious capabilities beyond the expected service inspection and command generation, but the description does not accurately represent the full actual-vs-declared scope because major advertised functions are absent.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 46)May include surrounding context.

Or use an expanded literal path:

bash
gsudo nssm set <service> Application "C:\ProgramData\chocolatey\bin\<exe>"

Topics

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 80)May include surrounding context.

Or use an expanded literal path:

bash
gsudo nssm set <service> Application "C:\ProgramData\chocolatey\bin\<exe>"

Topics

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 81)May include surrounding context.

Or use an expanded literal path:

bash
gsudo nssm set <service> Application "C:\ProgramData\chocolatey\bin\<exe>"

Topics

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 87)May include surrounding context.

Or use an expanded literal path:

bash
gsudo nssm set <service> Application "C:\ProgramData\chocolatey\bin\<exe>"

Topics

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · shawl-migration.md (reported line 112)May include surrounding context.

Or use an expanded literal path:

bash
gsudo nssm set <service> Application "C:\ProgramData\chocolatey\bin\<exe>"

Topics

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · update-path.md (reported line 50)May include surrounding context.

Or use an expanded literal path:

bash
gsudo nssm set <service> Application "C:\ProgramData\chocolatey\bin\<exe>"

Topics

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file instructs the operator to run administrator-privileged choco upgrade and nssm set/stop/start commands, which can modify installed software and Windows service configuration. Although privileges are noted, there is no explicit warning that these actions may change system state, restart services, or affect running applications.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The recovery section instructs users to run privileged package-management commands that can modify installed software and system state, including a bulk upgrade all, but it does not clearly warn about the scope of changes, package-script execution, or rollback precautions. In a troubleshooting skill, this is risky because users may treat the commands as harmless metadata repairs when they can trigger full installer/uninstaller actions with administrative rights.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
84% confidence
Finding

gsudo choco upgrade <pkg> -y elevates and performs a package upgrade non-interactively, which can execute installer/package scripts with administrative privileges. Although appropriate in some Windows package-management contexts, presenting it as the default recovery action without a stronger caution increases the chance of unintended privileged changes or abuse if <pkg> is user-controlled or copied blindly.

Content

Scanner excerpt · metadata-fix.md (reported line 55)May include surrounding context.

bash
# Invoke via PowerShell tool (bypass Bash escape)
gsudo choco upgrade <pkg> -y

After success, verify version match with choco list <pkg>.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
88% confidence
Finding

gsudo choco upgrade <pkg> -y --force is more dangerous than a normal upgrade because it intentionally re-runs package actions even when Chocolatey thinks the package is current. With admin rights, this can re-trigger install scripts, overwrite files, or cause service interruptions, so using it as a routine metadata-fix step is potentially unsafe.

Content

Scanner excerpt · metadata-fix.md (reported line 63)May include surrounding context.

2. Use --force (when 1 has no effect)

bash
gsudo choco upgrade <pkg> -y --force

--force re-runs the package stage even if already at the latest version to update .nuspec.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
93% confidence
Finding

gsudo choco upgrade all -y performs broad, privileged, unattended changes across all Chocolatey packages, greatly expanding blast radius beyond a single stale .nuspec. In the context of a metadata troubleshooting guide, this can unintentionally upgrade many unrelated applications, execute numerous package scripts, and destabilize the system.

Content

Scanner excerpt · metadata-fix.md (reported line 71)May include surrounding context.

3. Bulk Update

bash
gsudo choco upgrade all -y

Cleans up large amounts of outdated entries. Effective when UniGetUI has accumulated stale indicators.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · metadata-fix.md (reported line 84)May include surrounding context.

md
| # | Don't | Do |
|---|-------|-----|
| 1 | Repeatedly upgrade the same package in UniGetUI GUI | Run `gsudo choco upgrade <pkg> -y` directly in an elevated terminal |
| 2 | Directly edit `.nuspec` when suspecting metadata stale | Use `--force` so chocolatey performs a proper update |
| 3 | File an issue in the UniGetUI repository | UniGetUI is a passthrough — report to chocolatey-core (chocolatey/choco) or the package maintainer |
| 4 | Invoke `choco upgrade` from Bash (without elevation) | PowerShell tool + `gsudo` or administrator PowerShell |

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · metadata-fix.md (reported line 94)May include surrounding context.

md
| # | Don't | Do |
|---|-------|-----|
| 1 | Repeatedly upgrade the same package in UniGetUI GUI | Run `gsudo choco upgrade <pkg> -y` directly in an elevated terminal |
| 2 | Directly edit `.nuspec` when suspecting metadata stale | Use `--force` so chocolatey performs a proper update |
| 3 | File an issue in the UniGetUI repository | UniGetUI is a passthrough — report to chocolatey-core (chocolatey/choco) or the package maintainer |
| 4 | Invoke `choco upgrade` from Bash (without elevation) | PowerShell tool + `gsudo` or administrator PowerShell |

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · metadata-fix.md (reported line 95)May include surrounding context.

md
| # | Don't | Do |
|---|-------|-----|
| 1 | Repeatedly upgrade the same package in UniGetUI GUI | Run `gsudo choco upgrade <pkg> -y` directly in an elevated terminal |
| 2 | Directly edit `.nuspec` when suspecting metadata stale | Use `--force` so chocolatey performs a proper update |
| 3 | File an issue in the UniGetUI repository | UniGetUI is a passthrough — report to chocolatey-core (chocolatey/choco) or the package maintainer |
| 4 | Invoke `choco upgrade` from Bash (without elevation) | PowerShell tool + `gsudo` or administrator PowerShell |

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · metadata-fix.md (reported line 100)May include surrounding context.

md
| # | Don't | Do |
|---|-------|-----|
| 1 | Repeatedly upgrade the same package in UniGetUI GUI | Run `gsudo choco upgrade <pkg> -y` directly in an elevated terminal |
| 2 | Directly edit `.nuspec` when suspecting metadata stale | Use `--force` so chocolatey performs a proper update |
| 3 | File an issue in the UniGetUI repository | UniGetUI is a passthrough — report to chocolatey-core (chocolatey/choco) or the package maintainer |
| 4 | Invoke `choco upgrade` from Bash (without elevation) | PowerShell tool + `gsudo` or administrator PowerShell |

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · shawl-migration.md (reported line 152)May include surrounding context.

md
| # | Don't | Do |
|---|-------|-----|
| 1 | Repeatedly upgrade the same package in UniGetUI GUI | Run `gsudo choco upgrade <pkg> -y` directly in an elevated terminal |
| 2 | Directly edit `.nuspec` when suspecting metadata stale | Use `--force` so chocolatey performs a proper update |
| 3 | File an issue in the UniGetUI repository | UniGetUI is a passthrough — report to chocolatey-core (chocolatey/choco) or the package maintainer |
| 4 | Invoke `choco upgrade` from Bash (without elevation) | PowerShell tool + `gsudo` or administrator PowerShell |

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · shawl-migration.md (reported line 31)May include surrounding context.

If not installed → download from GitHub releases and place in ~/.local/bin/:

bash
mkdir -p ~/.local/bin && cd /tmp
curl -sL https://github.com/mtkennerly/shawl/releases/latest/download/shawl-v1.9.0-win64.zip -o shawl.zip
unzip -o shawl.zip
mv shawl.exe ~/.local/bin/

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · shawl-migration.md (reported line 38)May include surrounding context.

rm shawl.zip

text

(Based on v1.9.0. Query latest version via `https://api.github.com/repos/mtkennerly/shawl/releases/latest`)

## Migration Procedure

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The migration script explicitly stops and removes the existing Windows service registration via nssm.exe remove, which is a destructive action that can disrupt availability if the re-registration step fails or is applied to the wrong service. Although the surrounding text discusses migration, it does not prominently warn that the existing service definition will be deleted and should be backed up or validated first.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · shawl-migration.md (reported line 131)May include surrounding context.

md
|---|-------|-----|
| 1 | Leave shawl re-registration at LocalSystem (default) when existing nssm `ObjectName=.\USERNAME` | Specify the extracted value (`.\USERNAME`) explicitly via `sc.exe config obj=` |
| 2 | Assume "LocalSystem + `--home` specification" can serve as a workaround | `--home` only resolves config path — ownership/ACL problems of synced files are separate. User account execution is the proper fix |
| 3 | Hardcode plaintext password in script | Use `Read-Host -AsSecureString` or Group Managed Service Account (gMSA). If you must hardcode plaintext, apply `chmod 600` or `.gitignore` + remove immediately |
| 4 | Fail to update credentials when user password changes → service fails to start | Immediately update via `sc.exe config <svc> password= <new_pw>`. Be aware of Windows password rotation policy |

#### Verification After User Account Registration

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · shawl-migration.md (reported line 195)May include surrounding context.

md
- shawl add --name syncthing -- syncthing.exe --no-browser --home=...AppData\Local\Syncthing
- Service RUNNING + 8384 LISTENING recovery complete.

**2026-05-21 (2nd occurrence)**: Immediately after the 1st migration in the same session, `choco upgrade` or auto-upgrade transitioned syncthing 2.1.0 → 2.1.1. The shawl service was automatically removed by chocolateyBeforeModify. `sc query` showed service does not exist. Recovered via re-registration. → Created the "Follow-up Case" section in this topic.

**2026-05-21 (3rd occurrence)**: During 1st/2nd shawl re-registration, the existing nssm `ObjectName=.\<USERNAME>` was not extracted/preserved and was registered with the default LocalSystem. Risk of owner/permission mismatch for services like syncthing that sync user data. User pointed out "registered with the wrong user". Reinforced by adding ObjectName extraction in the diagnosis step + `sc.exe config obj=` step in the migration script + restructuring the execution account decision table.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file describes running privileged commands that stop and modify a service, which can affect system availability and service continuity. Although the commands are central to the skill's purpose, the document does not include a user-facing warning that the action will temporarily interrupt the service and change its configuration.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/nssm-manager.js:22