T05 · Unauthorized Access and Privilege Escalation
- Location
references/modules/module-31-轻量常驻监控.md:108- Finding
Highest-privilege SYSTEM scheduled task executes a user-profile PowerShell script
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This Windows admin skill has a legitimate purpose, but its safety labels understate powerful actions such as persistent scheduled tasks, fleet-wide remote commands, credential handling, webhook egress, and destructive cleanup.
Review carefully before installing. Use only in a controlled admin environment, avoid production cleanup/remote-command/monitoring modules unless you have explicit approvals, and do not store privileged credentials or webhook secrets through the provided snippets without stronger scoping, cleanup, and least-privilege controls.
references/modules/module-31-轻量常驻监控.md:108Highest-privilege SYSTEM scheduled task executes a user-profile PowerShell script
references/modules/module-28-性能基线-&-趋势分析.md:33Read-only performance analysis silently registers a persistent scheduled task
references/modules/module-30-远程多服务器管理.md:118Unvalidated commands are executed with administrator credentials across every registered server
references/modules/module-30-远程多服务器管理.md:44Administrative password is exposed as a process command-line argument
references/modules/module-27-自动化修复向导.md:369Temporary-file cleanup permanently deletes all unrelated Recycle Bin contents
references/modules/module-33-告警推送.md:21Webhook bearer secret is stored in plaintext and the destination is not validated
YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).
}
### 20.3 远程域名证书探测(本地无证书的站点)
```powershell
# 将下方域名替换为你需要检测的站点
$domains = @('www.baidu.com', 'www.taobao.com') # 示例,替换为你的域名
Write-Host "════════ 远程域名 SSL 证书检测 ════════"
foreach ($domain in $domains) {
try {
$tcpClient = New-Object System.Net.Sockets.TcpClient($domain, 443)
$sslStream = New-Object System.Net.Security.SslStream($tcpClient.GetStream(), $false, { $true })
$sslStream.AuthenticateAsClient($domain)
$cert = $sslStream.RemoteCertificate
$expiry = [DateTime]::Parse($cert.GetExpirationDateString())
$daysLeft = ($expiry - (Get-Date)).Days
$status = if ($daysLeft -lt 0) { '❌ 已过期' }
elseif ($daysLeft -lt 30) { '⚠️ 即将过期' }
else { '✅ 正常' }
Write-Host " $domain → 到期: $($expi
YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).
}
### 20.3 远程域名证书探测(本地无证书的站点)
```powershell
# 将下方域名替换为你需要检测的站点
$domains = @('www.baidu.com', 'www.taobao.com') # 示例,替换为你的域名
Write-Host "════════ 远程域名 SSL 证书检测 ════════"
foreach ($domain in $domains) {
try {
$tcpClient = New-Object System.Net.Sockets.TcpClient($domain, 443)
$sslStream = New-Object System.Net.Security.SslStream($tcpClient.GetStream(), $false, { $true })
$sslStream.AuthenticateAsClient($domain)
$cert = $sslStream.RemoteCertificate
$expiry = [DateTime]::Parse($cert.GetExpirationDateString())
$daysLeft = ($expiry - (Get-Date)).Days
$status = if ($daysLeft -lt 0) { '❌ 已过期' }
elseif ($daysLeft -lt 30) { '⚠️ 即将过期' }
else { '✅ 正常' }
Write-Host " $domain → 到期: $($expi
The disk-cleanup flow performs irreversible deletion of temp files and empties the recycle bin, directly contradicting the parent claim that the tool is read-only and will not delete files. In an agent setting, this can cause unintended data loss because operators may invoke the skill believing it is safe from deletion.
The module advertises the toolbox as '只读分析+安全确认,绝不误删文件', yet this file defines active repair workflows that stop services, reset network state, and delete files. This mismatch is dangerous because users or higher-level agents may grant trust and permissions under a read-only assumption, leading to unexpected system changes.
The module explicitly claims all operations are read-only, but the code creates directories, writes CSV files, and registers a scheduled task that persists for 7 days. This mismatch can mislead operators or higher-level agents into granting execution under a lower-risk assumption, while the code actually performs persistent state changes and ongoing data collection.
The safety statement and the implementation are directly contradictory: the module says it will not modify system configuration, yet it installs a scheduled task and writes output files. Such deceptive or inaccurate safety labeling undermines trust boundaries and may cause unauthorized persistence on systems where only non-mutating diagnostics were expected.
The module explicitly claims all operations are read-only, but later includes report-generation code that creates a directory and writes a Markdown file under the user's profile. This mismatch can mislead users or orchestration systems into granting trust or permissions they would not otherwise allow, undermining safety guarantees even if the write is only local output.
The manifest marks the skill as readonly, yet the code creates a directory and writes a file to disk during normal report generation. In agent environments, mode flags may be used as trust boundaries; violating them can bypass policy expectations, cause unintended persistence, and enable follow-on abuse if other components rely on the readonly declaration.
This module advertises read-only/safe-confirm behavior, but section 30.2 enables arbitrary command execution across multiple remote servers via Invoke-Command and Invoke-Expression. That creates a direct capability for state-changing administration, destructive actions, or lateral movement, and the misleading safety claims increase the chance that an agent or operator will invoke it under false assumptions.
The documentation states that many administrative changes are unsupported and that the tool is read-only, yet this module explicitly supports remote management workflows that can alter state on many systems. This mismatch is dangerous because users and calling agents may trust the policy text while the actual module exposes mechanisms for credential storage, remoting, and arbitrary command execution.
The module is labeled mode: readonly, but it creates files under the user profile and installs a recurring scheduled task running as SYSTEM with ExecutionPolicy Bypass. That is a significant privilege and persistence mismatch: users or higher-level agents may trust the metadata and invoke it expecting non-mutating behavior, while it actually establishes privileged long-term execution.
The skill metadata and description claim the toolbox runs completely offline, but this module explicitly sends alert contents to external enterprise webhook endpoints using Invoke-RestMethod. That mismatch can mislead operators into enabling the skill in restricted or sensitive environments, causing unintended network egress and disclosure of hostnames, metrics, threshold values, and operational recommendations to third-party services.
The display name, descriptions, quick-start prompts, and operational guidance are all written in Chinese, including an instruction that users can 'directly speak to AI' using Chinese examples. The file does not offer multilingual usage, an opt-in language preference, or a documented reason that the skill must be Chinese-only, which can violate language/locale policy expectations.
The skill claims '完全免费离线运行/无需联网', yet later advertises remote multi-server management and webhook-based alert delivery. This mismatch is security-relevant because users may deploy the skill in restricted or sensitive environments assuming there is no outbound communication capability, when in fact network-capable features exist.
The quick-start phrases are broad natural-language prompts such as checking disks, IIS, or cleanup, which increases the chance of accidental invocation by an agent or user in ordinary conversation. In a skill that includes cleanup, service inspection, and potentially repair workflows, unintended triggering can lead to unnecessary data collection or progression toward impactful actions.
The skill explicitly presents itself as '只读诊断' and '不修改任何文件', but the logging function creates directories, appends to a log file, rotates logs, and deletes old log files. This is a real integrity/trust issue because users and calling agents may rely on the documented safety boundary when deciding whether to invoke the skill.
The description does not prominently warn users that the skill may persist telemetry/logs locally and may send alerts externally via webhooks. Missing disclosure undermines informed consent and can cause inappropriate use in regulated or isolated environments where persistence and egress are tightly controlled.
The description explicitly presents the skill as a Windows Server CIS baseline in Chinese, and all user-facing content items are also written only in Chinese. This creates a language/locale constraint without any opt-in, alternative language option, or documented region-specific justification in the file.
The standard name and description are presented only in Chinese, and the file gives no indication that the locale is optional or that the skill is region-specific. Under the language/locale policy, forcing a specific language without user opt-in or clear documented justification is a policy concern.
The trigger phrases are broad, natural-language requests that are likely to appear in normal support conversations. In an automation context, this can cause unintended invocation of a cleanup workflow that leads to scanning or deletion actions when the user intended a discussion, diagnosis, or narrower operation.
The module promises preview-first cleanup with explicit user confirmation, but the second PowerShell block contains immediately runnable deletion logic with only a comment as a safeguard. In an agent or copy-paste workflow, comments do not enforce policy, so the destructive action could run without a verified confirmation step or without a trustworthy preview context.
The module documentation claims broader 'safe cleanup' coverage across multiple sensitive temporary locations, but the preview script only enumerates the current user's %TEMP% directory. This mismatch can mislead an operator or downstream agent into believing all listed paths were reviewed before cleanup, increasing the chance of deleting files from unreviewed locations if the deletion phase is adapted or invoked with a broader file set.
The trigger phrase '看看各个目录的空间占用' is broad and could activate the module in contexts where the user did not explicitly intend this specific disk-usage report. Overly permissive activation boundaries can cause unintended execution of filesystem enumeration logic, which may expose directory size information from sensitive paths such as C:\Users, ProgramData, or IIS-related folders.
All user-facing descriptions, triggers, warnings, and instructions are presented in Chinese, and the file does not indicate that the skill is intended only for Chinese-speaking users or provide an opt-in language choice. That can conflict with organizational language/locale policy requiring user choice or explicit justification.
The module metadata and description claim 'readonly' and '只读分析+安全确认', but the documented workflow includes stopping a Windows service, deleting update cache files, and restarting the service. This mismatch can cause an orchestrator or user to trust the module as non-mutating when it actually contains destructive operational steps, increasing the risk of unintended state changes on production systems.
No suspicious patterns detected.