T06 · System Persistence
- Location
SKILL.md:96- Finding
Persistent Subscription-Backed Proxy Installed as an Automatic User Service
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:96-120
Vulnerability Type: Persistent user-level service
Risk Level: HighVulnerable Code
bash # Create systemd user service # Adjust paths below to match your system — find yours with: # which claude-max-api # echo $HOME mkdir -p ~/.config/systemd/user cat > ~/.config/systemd/user/claude-max-api-proxy.service << EOF [Unit] Description=Claude Max API Proxy After=network.target [Service] Type=simple ExecStart=$(which claude-max-api) Environment=HOME=$HOME Environment=PATH=$HOME/.npm-global/bin:/usr/local/bin:/usr/bin:/bin Restart=on-failure RestartSec=5 [Install] WantedBy=default.target EOF systemctl --user daemon-reload systemctl --user enable claude-max-api-proxy systemctl --user start claude-max-api-proxyTechnical Analysis
The instructions create, enable, and immediately start a systemd user service for the proxy. The
WantedBy=default.targetconfiguration andsystemctl --user enablecommand cause the proxy to start automatically in future user sessions.Restart=on-failurefurther extends its availability by restarting it after failures.This service exposes functionality backed by the user's authenticated Claude CLI session. Although persistence is presented as optional and serves the stated proxy use case, it expands the proxy's lifetime beyond the immediate setup session and creates a durable access path to the user's subscription.
The interpolated
ExecStart=$(which claude-max-api)value also permanently trusts whichever matching executable is first inPATHwhen the service file is generated. The principal confirmed issue, however, is the deliberate cross-session service installation.Attack Path
- A user follows the optional persistent-service instructions.
- The Skill writes a service definition under
~/.config/systemd/user/. - The service is enabled for future user sessions ...[truncated 888 chars]
- Remediation
View remediation
Remediation Suggestions
-
Default to running the proxy as an explicit foreground process whose lifetime is limited to the current terminal session.
-
Remove automatic service creation and enablement from the standard setup path.
-
If persistence is required, obtain explicit informed confirmation before creating the service.
-
Require authentication on the proxy before enabling automatic startup.
-
Run the service under a dedicated, restricted account where practical.
-
Apply systemd hardening directives such as
NoNewPrivileges=true,PrivateTmp=true,ProtectSystem=strict, and a narrowly scopedReadWritePaths. -
Resolve and validate the executable path from a trusted installation directory rather than relying on an unrestricted
whichlookup. -
Document complete removal instructions, including disabling and deleting the service:
bash systemctl --user disable --now claude-max-api-proxy rm -f ~/.config/systemd/user/claude-max-api-proxy.service systemctl --user daemon-reload
-
