T06 · System Persistence
- Location
SKILL.md:55- Finding
Persistent Scheduled Execution of External Synchronization Commands
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill has a legitimate stats-sync purpose, but it recommends recurring execution of an unpinned npm package and under-explains what local session data is uploaded.
Review carefully before installing. Prefer a pinned, reviewed Code Card CLI version, avoid printing the API key, confirm exactly what session data is uploaded, and do not add the cron jobs unless you accept unattended recurring syncs.
SKILL.md:55Persistent Scheduled Execution of External Synchronization Commands
SKILL.md:29Runtime Download and Execution of an Unpinned npm Package
SKILL.md:21API Key Disclosed Through Configuration File Output
SKILL.md:29Opaque Full Upload of Local Coding-Session Data
The skill instructs access to ~/.claude/.codecard, which is inside an agent configuration directory and may contain API credentials. Even though the example only reads a specific file, normalizing direct inspection of config directories increases the chance of credential disclosure in chat logs, terminal captures, or accidental over-broad file access patterns.
Check if already configured:
cat ~/.claude/.codecard 2>/dev/null
If it prints CC_API_KEY=cc_..., skip to the Sync section.
The skill states it syncs AI coding stats and sessions to an external service, but it does not provide a clear privacy warning describing what data leaves the machine, where it is sent, or how it is handled. Users may unknowingly expose sensitive coding metadata, prompts, filenames, or activity patterns to a third party without informed consent.
The skill instructs users to run npx code-card@latest, which fetches and executes the latest package version at runtime. This creates a supply-chain risk: if the package is compromised, typosquatted, or publishes a malicious update, arbitrary code would execute on the user's machine without review.
This command uses npx code-card@latest sync -i, which downloads and executes the newest published package version every time it runs. Because it is intended for repeated sync operations, it expands the attack surface for malicious package updates or registry compromise into a recurring remote-code-execution path.
The full resync command again executes npx code-card@latest, inheriting the same unpinned package execution risk. A full sync may also process more local data, making a compromised package especially sensitive because it can access a broader set of coding-session information during execution.
The stats example uses npx code-card@latest, so even a read-oriented command still causes execution of unreviewed latest code from the registry. Although the functional purpose appears benign, it still grants arbitrary code execution capability to whatever package version is served at invocation time.
The profile command also uses npx code-card@latest, preserving the same dynamic package execution risk. Even though the command's goal is just to open a profile, a compromised package could perform unrelated malicious actions locally before or instead of that behavior.
The cron job message schedules recurring execution of npx code-card@latest sync -i, turning the unpinned supply-chain risk into an automated persistence mechanism. Once scheduled, any future malicious package update could execute regularly without additional user scrutiny.
This weekly cron example automates npx code-card@latest sync, creating a long-lived recurring path for unreviewed code execution from the package registry. The scheduled nature makes the context more dangerous than an interactive one-off command because compromise can trigger later and repeatedly.
No suspicious patterns detected.