Back to skill

Security audit

playcover-cli

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only PlayCover CLI guide whose powerful app-management commands are expected for its purpose, but users should treat uninstall, cleanup, config, download, and dylib operations carefully.

Install only if you are comfortable letting an agent advise on PlayCover CLI administration. Before running generated commands, verify bundle IDs and paths, back up app data/keymaps/settings before uninstall or reset operations, use trusted IPA and dylib sources, and be cautious with global config keys that suppress prompts or clear data during uninstall.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (16)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

This is a markdown file, so SQP-2 applies to omissions in the skill description. The command reference lists operations that can remove apps, delete data, or alter configuration, but the document does not warn users that these actions may be destructive or irreversible.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The uninstall documentation states that app data, settings, entitlements, and related artifacts are removed by default, but it does not present this as a prominent destructive-action warning. In an AI-agent, CI, or shell-script context, users may invoke the command assuming a standard uninstall and unintentionally trigger irreversible data loss, especially because automation may not include an interactive confirmation step.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The markdown describes clear-cache as clearing an installed app's caches and clear-play-chain as clearing per-app state, but it does not warn that these actions remove app data and may affect app behavior or reset state. Because markdown files should disclose behaviors that can affect user data or system integrity, this omission is a safety concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The description states that prune will remove stale keymaps, settings, entitlements, containers, and PlayChain data, but it frames the command as 'safe to run periodically' without an explicit warning that files are being deleted. For markdown documentation, destructive cleanup behavior should be clearly disclosed so users understand the risk before running it automatically.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file documents settings set and settings reset, which can change app behavior and, for metalHUD, trigger a system-wide side effect. While the side effect is mentioned, there is no user-facing caution or warning section explaining the impact of modifying settings or resetting all settings to defaults.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file documents a command that writes global preferences shared across all apps, and the allowed keys include settings that suppress install/uninstall prompts and clear app data on uninstall. Under SQP-2 for markdown files, the description should warn users about behaviors that can affect user data or system integrity, but no such warning is provided.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file documents operations that copy a dynamic library into an app install and later remove it, which can affect app behavior and system integrity. The description provides usage and outputs but does not warn users that these actions modify installed apps and may cause instability or unintended side effects.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 88)May include surrounding context.

md
# `keymap` — manage keymaps

Per-app keyboard mapping management. A "keymap" is a `.playmap` (or legacy `.plist`) file mapping keyboard keys to touch coordinates and actions for an iOS app running under PlayCover.

The `keymap` command is a **group** with eight subcommands. `<bundleId>` identifies the app; `<name>` is the keymap's local name within that app.

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 89)May include surrounding context.

md
# `keymap` — manage keymaps

Per-app keyboard mapping management. A "keymap" is a `.playmap` (or legacy `.plist`) file mapping keyboard keys to touch coordinates and actions for an iOS app running under PlayCover.

The `keymap` command is a **group** with eight subcommands. `<bundleId>` identifies the app; `<name>` is the keymap's local name within that app.

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.zh-CN.md (reported line 88)May include surrounding context.

md
# `keymap` — manage keymaps

Per-app keyboard mapping management. A "keymap" is a `.playmap` (or legacy `.plist`) file mapping keyboard keys to touch coordinates and actions for an iOS app running under PlayCover.

The `keymap` command is a **group** with eight subcommands. `<bundleId>` identifies the app; `<name>` is the keymap's local name within that app.

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.zh-CN.md (reported line 89)May include surrounding context.

md
# `keymap` — manage keymaps

Per-app keyboard mapping management. A "keymap" is a `.playmap` (or legacy `.plist`) file mapping keyboard keys to touch coordinates and actions for an iOS app running under PlayCover.

The `keymap` command is a **group** with eight subcommands. `<bundleId>` identifies the app; `<name>` is the keymap's local name within that app.

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/keymaps.md (reported line 3)May include surrounding context.

md
# `keymap` — manage keymaps

Per-app keyboard mapping management. A "keymap" is a `.playmap` (or legacy `.plist`) file mapping keyboard keys to touch coordinates and actions for an iOS app running under PlayCover.

The `keymap` command is a **group** with eight subcommands. `<bundleId>` identifies the app; `<name>` is the keymap's local name within that app.

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/keymaps.md (reported line 78)May include surrounding context.

md
# `keymap` — manage keymaps

Per-app keyboard mapping management. A "keymap" is a `.playmap` (or legacy `.plist`) file mapping keyboard keys to touch coordinates and actions for an iOS app running under PlayCover.

The `keymap` command is a **group** with eight subcommands. `<bundleId>` identifies the app; `<name>` is the keymap's local name within that app.

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/keymaps.md (reported line 84)May include surrounding context.

md
# `keymap` — manage keymaps

Per-app keyboard mapping management. A "keymap" is a `.playmap` (or legacy `.plist`) file mapping keyboard keys to touch coordinates and actions for an iOS app running under PlayCover.

The `keymap` command is a **group** with eight subcommands. `<bundleId>` identifies the app; `<name>` is the keymap's local name within that app.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file documents a reset operation that clears custom bindings, which can affect user data/state. Although the behavior is briefly described, it does not provide an explicit warning or caution about the destructive effect before use.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

文件整体以中文编写并作为技能说明文档提供,但未说明这是可选语言版本、也未给出用户语言偏好或替代语言入口。根据规则,强制特定语言而无用户选择可能构成自然语言层面的语言/地区策略问题。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.