T06 · System Persistence
- Location
README.md:167- Finding
Persistent Autonomous AI Loop Installed as a System Service
- Content
View full analysis
Vulnerability Details
File Location:
README.md, lines 167–187
Vulnerability Type: System persistence through a boot-enabled systemd service
Risk Level: CriticalVulnerable Code
bash # Create service file sudo tee /etc/systemd/system/ralph-loop.service << 'EOF' [Unit] Description=Ralph AI Loop After=network.target [Service] Type=simple User=YOUR_USER WorkingDirectory=/path/to/project ExecStart=/path/to/ralph.sh 50 Restart=on-failure RestartSec=30 Environment=RALPH_CLI=codex [Install] WantedBy=multi-user.target EOF sudo systemctl daemon-reload sudo systemctl enable ralph-loop sudo systemctl start ralph-loopTechnical Analysis
The documentation instructs users to create a root-owned systemd unit, enable it at boot, and automatically restart it after failures. The service executes an autonomous AI coding loop that reads mutable project instructions and may modify code, run project commands, and commit changes.
Installing a system-wide boot service is not required for the Skill’s core declared purpose of generating and running Ralph loop scripts. A manually launched process, user-scoped transient unit, terminal multiplexer, or container would provide long-running operation without modifying global startup configuration.
Although
User=YOUR_USERmeans the loop should run as the configured non-root account, creating and enabling the service requires root privileges. The resulting process survives shell termination and host reboot, removing the normal interactive boundary associated with starting each run.Attack Path
- A user follows the documented setup using
sudo. - A root-owned service definition is written to
/etc/systemd/system/ralph-loop.service. systemctl enableregisters the loop to start during future boots.- The service launches
ralph.sh, which repeatedly starts an AI coding agent. - The agent consumes mutable project files such as
PROMPT.md,AGENTS.md, specifications, and the implementation ...[truncated 1097 chars]
- A user follows the documented setup using
- Remediation
View remediation
Remediation Suggestions
- Remove system-wide boot persistence instructions from the standard workflow.
- Do not recommend
systemctl enablefor an autonomous coding agent. - If restart support is essential, use an explicitly opt-in user-scoped service under
~/.config/systemd/user/. - Prefer a transient unit such as
systemd-run --userwithout boot enablement. - Require explicit confirmation before every new loop run.
- Run the agent inside a container or VM with only the intended project directory mounted.
- Apply systemd hardening where supported, including:
NoNewPrivileges=truePrivateTmp=trueProtectSystem=strictProtectHome=read-onlyReadWritePaths=/path/to/projectRestrictSUIDSGID=trueMemoryMax=...CPUQuota=...RuntimeMaxSec=...
- Use an absolute, administrator-reviewed script path and ensure it is not writable by less-trusted users.
- Document removal and rollback commands for any service that users install.
- Avoid automatic restart unless a bounded retry count or rate limit is enforced.
