Back to skill

Security audit

fluxmount

Security checks for vulnerabilities and agentic risk

Overview

FluxMount appears to provide the advertised macOS NTFS read/write mounting workflow, but it also installs persistent passwordless privileged disk-mounting components and uses mutable third-party dependency sources.

Install only if you are comfortable with a local macOS disk utility adding a LaunchAgent, a passwordless sudoers entry, third-party filesystem drivers, and automatic handling of connected NTFS volumes. Prefer running the dry-run first, review the exact files and sudoers rule, back up important data, verify dependency sources yourself, and remove it with uninstall.sh when no longer needed.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T03 · Remote Payload Retrieval and Execution

Error
Location
scripts/install.sh:27
Finding

Privileged installation of remotely retrieved packages from mutable third-party mirrors

Content
View full analysis
/dev/null && [ -s "/tmp/$MACFUSE_DMG" ]; then dmg="/tmp/$MACFUSE_DMG" break fi done xattr -d com.apple.quarantine "$dmg" 2>/dev/null || true mnt=$(hdiutil attach "$dmg" -nobrowse -noautoopen 2>/dev/null | awk -F'\t' '/Volumes/{print $NF}') pkg=$(find "$mnt" -maxdepth 2 -name '*.pkg' 2>/dev/null | head -1) if command -v pkgutil >/dev/null 2>&1 && pkgutil --check-signature "$pkg" >/dev/null 2>&1; then echo " Package signature validation passed" else hdiutil detach "$mnt" >/dev/null 2>&1 || true exit 1 fi sudo installer -pkg "$pkg" -target / >/dev/null 2>&1 hdiutil detach "$mnt" >/dev/null 2>&1 || true ``` ### Technical Analysis The installer downloads a macFUSE disk image through multiple mutable, third-party GitHub proxy services and subsequently installs a package from that image with root privileges. The script does not verify a pinned cryptographic digest for the DMG or package. Its `pkgutil --check-signature` call only checks whether macOS recognizes a package signature; it does not explicitly compare the signer identity or Team ID against a hardcoded expected macFUSE publisher. The script also follows r ...[truncated 1553 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
scripts/install.sh:139
Finding

Unpinned third-party Homebrew tap introduces mutable supply-chain code

Content
View full analysis
/dev/null 2>&1 && [ ! -x /usr/local/bin/ntfs-3g ]; then if command -v brew >/dev/null 2>&1; then HOMEBREW_NO_AUTO_UPDATE=1 brew tap gromgit/homebrew-fuse 2>&1 | tail -1 if HOMEBREW_NO_AUTO_UPDATE=1 brew install ntfs-3g-mac 2>&1 | tail -3; then echo " ntfs-3g installation completed" else echo " Homebrew installation failed" fi fi if ! command -v ntfs-3g >/dev/null 2>&1 && [ ! -x /usr/local/bin/ntfs-3g ]; then exit 1 fi fi ``` ### Technical Analysis The installer adds the mutable `gromgit/homebrew-fuse` third-party tap and installs its current `ntfs-3g-mac` formula. It does not pin a reviewed tap commit, formula revision, package version, source archive digest, or bottle digest in the Skill itself. Homebrew formulae can execute build and installation logic and can introduce further dependencies. Consequently, compromise of the tap repository, maintainer account, release artifacts, or dependency chain could change the code installed by the Skill after the Skill itself has passed review. The dependency is functionally relevant to NTFS mounting, but using a mutable third-party source without artifact pinning is not the minimum-risk installation design. ### Attack Path 1. An attacker compromises the third-party tap, a maintainer account, or an artifact referenced by the formula. 2. The attacker modifies the formula or package content while retaining the expected formula name. 3. A user runs `install.sh`. 4. The script taps the current repository state and installs the current `ntfs-3g-mac` formula. 5. Homebrew processes the malicious formula, build instructions, package scripts, or dependencies. 6. The installed binary is later invoked by the passwordless privileged mount helper, potential ...[truncated 519 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/mount-ntfs-rw:61
Finding

Passwordless root helper relies on environment-based executable resolution

Content
View full analysis
/dev/null sudo chmod 440 "$SUDOERS" ``` ```bash NTFS_3G="$(command -v ntfs-3g 2>/dev/null || true)" [ -z "$NTFS_3G" ] && NTFS_3G="/usr/local/bin/ntfs-3g" diskutil unmount "$mp" >/dev/null 2>&1 || sudo umount "$mp" >/dev/null 2>&1 sudo mkdir -p "$target" 2>/dev/null || true for attempt in 1 2 3; do if sudo "$NTFS_3G" "$dev" "$target" -o rw,auto_xattr,auto_cache,local,allow_other 2>/dev/null; then probe="$target/.fluxmount_rw_test_$(date +%s)" if touch "$probe" 2>/dev/null; then rm -f "$probe" ok=1 break fi fi done ``` ### Technical Analysis The installer grants the invoking user permanent passwordless execution of the entire `mount-ntfs-rw` shell script as root. That script then resolves `ntfs-3g` using `command -v` and invokes several other utilities by unqualified name. The practical exploitability of path substitution depends on the host's sudo `secure_path`, environment-reset rules, filesystem ownership, and executable search path. Nevertheless, a passwordless root entry point should not depend on ambient executable resolution. Nested `sudo` calls inside a script that is already authorized to run as root also make the privilege boundary harder to reason about. The script does not verify that the selected `ntfs-3g` executable is root-owned, non-writable by ordinary users, signed by an expected publisher, or equal to an approved digest. ### Attack Path 1. An attacker gains the ability to place or replace an executable in a directory searched by the privileged helper, ...[truncated 967 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/install.sh:186
Finding

Persistent automatic disk access is combined with passwordless elevation and broad access guidance

Content
View full analysis
"$AGENT_PLIST" < Label$AGENT_LABEL ProgramArguments $AUTO_SH RunAtLoad StartOnMount StandardErrorPath/tmp/fluxmount.log StandardOutPath/tmp/fluxmount.log PLIST launchctl bootout "gui/$(id -u)/$AGENT_LABEL" 2>/dev/null || true launchctl bootstrap "gui/$(id -u)" "$AGENT_PLIST" 2>/dev/null ``` ```bash LOG="/tmp/fluxmount.log" echo "[$(date)] FluxMount: automatic mount triggered" >> "$LOG" /usr/local/bin/mount-ntfs-rw >> "$LOG" 2>&1 echo "[$(date)] FluxMount: exit status $?" >> "$LOG" ``` The troubleshooting guidance additionally recommends granting Full Disk Access to: ```text /usr/local/bin/ntfs-automount /usr/local/bin/mount-ntfs-rw /usr/local/bin/ntfs-3g ``` The privileged mount operation uses: ```bash sudo "$NTFS_3G" "$dev" "$target" -o rw,auto_xattr,auto_cache,local,allow_other ``` ### Technical Analysis The LaunchAgent persistence mechanism is explicitly disclosed and is relevant to the advertised boot-time and hot-plug automatic mounting feature. It is therefore not covert persistence by itself. The security concern is the combined privilege model: the agent runs at login and on mount events, invokes a helper authorized through passwordless sudo, mounts filesystems with `allow_other`, and the documentation recommends granting Full Disk Access to three executables. This cre ...[truncated 1580 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (118)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents FluxMount as an end-user macOS NTFS read/write mounting solution. However, the provided code chunk does not implement NTFS support, mounting, installation, health checks, auto-mount behavior, or uninstall logic. Instead, it is a release/deployment helper script whose sole purpose is to publish the skill to ClawHub using preset metadata. That is a materially different primary purpose from the declared user-facing functionality, so this code chunk does not accurately represent the described behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents the skill as a local macOS NTFS read/write mounting solution for external drives. However, the supplied code chunk is only a deployment helper script for packaging and uploading the skill to Qoder Cloud. Its primary function is remote distribution, not mounting NTFS volumes or managing macOS disk behavior. This is a material purpose mismatch: the code accesses network resources and an API token, while the description focuses on local disk mounting functionality. Even though this may be ancillary project infrastructure, the requested comparison is between the declared skill purpose and this code chunk’s actual behavior, and they do not match.

Content

No source excerpt is available for this finding.

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · DEPLOY.md (reported line 72)May include surrounding context.

md
-H "Authorization: Bearer $QODER_PAT" \
  -F "name=fluxmount" \
  -F "type=custom" \
  -F "description=FluxMount - macOS NTFS read-write skill by Changyu Zhang" \
  -F "file=@fluxmount-qoder.zip"

echo ""

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · PUBLISH.md (reported line 79)May include surrounding context.

md
-H "Authorization: Bearer $QODER_PAT" \
  -F "name=fluxmount" \
  -F "type=custom" \
  -F "description=FluxMount - macOS NTFS read-write skill by Changyu Zhang" \
  -F "file=@fluxmount-qoder.zip"

echo ""

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · deploy/qoder.sh (reported line 26)May include surrounding context.

sh
-H "Authorization: Bearer $QODER_PAT" \
  -F "name=fluxmount" \
  -F "type=custom" \
  -F "description=FluxMount - macOS NTFS read-write skill by Changyu Zhang" \
  -F "file=@fluxmount-qoder.zip"

echo ""

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · scripts/install.sh (reported line 62)May include surrounding context.

sh
echo -n "ntfs-3g 程序:      "; command -v ntfs-3g >/dev/null 2>&1 && echo "✅ $(ntfs-3g --version 2>/dev/null | head -1)" || ([ -x /usr/local/bin/ntfs-3g ] && echo "✅ /usr/local/bin/ntfs-3g" || echo "❌ 未装")

  echo -n "脚本就位:          "; [ -x "$MOUNT_SH" ] && [ -x "$AUTO_SH" ] && echo "✅" || echo "❌ 缺失"
  echo -n "免密 sudo:         "; sudo -n "$MOUNT_SH" --check >/dev/null 2>&1 && echo "✅" || echo "⚠️ 未配置(自动挂载会需密码)"

  local agent; agent=$(launchctl list 2>/dev/null | grep -c "$AGENT_LABEL")
  echo -n "自动挂载代理:      "; [ "$agent" -gt 0 ] && echo "✅ 已注册" || echo "❌ 未注册"

Chaining Abuse

High
Category
Tool Misuse
Confidence
96% confidence
Finding

Piping generated content directly into 'sudo tee' writes a new sudoers rule without validation, creating a risky privilege-granting chain. If variables or the target path were malformed, or if the resulting sudoers syntax were wrong, this could break sudo policy or create an unintended root execution pathway; in this installer, that chain is especially sensitive because it establishes persistent passwordless root access.

Content

Scanner excerpt · scripts/install.sh (reported line 174)May include surrounding context.

sh
echo "  ✅ 脚本已装到 $BIN"

# 免密 sudo (仅放行 mount-ntfs-rw)
echo "$USER ALL=(root) NOPASSWD: $MOUNT_SH" | sudo tee "$SUDOERS" >/dev/null
sudo chmod 440 "$SUDOERS"
echo "  ✅ 已配置免密 sudo (自动挂载不会弹密码框)"

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/install.sh (reported line 184)May include surrounding context.

sh
launchctl bootout "gui/$(id -u)/com.user.ntfs-automount" 2>/dev/null || true
  rm -f "$OLD_AGENT"
fi
[ -f /etc/sudoers.d/ntfs-automount ] && sudo rm -f /etc/sudoers.d/ntfs-automount

# LaunchAgent plist
cat > "$AGENT_PLIST" <<PLIST

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · scripts/install.sh (reported line 184)May include surrounding context.

sh
launchctl bootout "gui/$(id -u)/com.user.ntfs-automount" 2>/dev/null || true
  rm -f "$OLD_AGENT"
fi
[ -f /etc/sudoers.d/ntfs-automount ] && sudo rm -f /etc/sudoers.d/ntfs-automount

# LaunchAgent plist
cat > "$AGENT_PLIST" <<PLIST

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · scripts/mount-ntfs-rw (reported line 93)May include surrounding context.

text
[ -z "$mp" ] && continue
    if mount | grep -qF "$mp"; then
      echo "  💿 安全弹出: $mp"
      diskutil unmount "$mp" >/dev/null 2>&1 || sudo umount "$mp" >/dev/null 2>&1
    fi
  done < "$STATE_FILE"
  sudo rm -f "$STATE_FILE" 2>/dev/null || true

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · scripts/uninstall.sh (reported line 28)May include surrounding context.

sh
[ -z "$mp" ] && continue
    if mount | grep -qF "$mp"; then
      echo "  💿 安全弹出: $mp"
      diskutil unmount "$mp" >/dev/null 2>&1 || sudo umount "$mp" >/dev/null 2>&1
    fi
  done < "$STATE_FILE"
  sudo rm -f "$STATE_FILE" 2>/dev/null || true

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Line L08 states that error messages must be in Chinese for end users. This is a natural-language locale policy constraint applied globally, and the file does not indicate user opt-in, multilingual support, or a clearly justified region-specific requirement.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document claims the commands 'do not affect any machine configuration,' but the same file instructs users to publish artifacts, authenticate to third-party services, and modify remote service state. This is misleading because it can cause users to underestimate the security and privacy consequences of executing the commands, including unintended disclosure of repository contents and account-linked changes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The instruction to directly upload the entire repository folder lacks any warning to inspect the archive for secrets, local paths, test artifacts, or unintended files. In a publishing workflow, this can lead to accidental exfiltration of sensitive materials to a public or third-party registry.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · DEPLOY.md (reported line 68)May include surrounding context.

或手动上传(zip 已就绪于 /Users/matiansa/cy/c/fluxmount-qoder.zip):

bash
curl -X POST "https://api.qoder.com/api/v1/cloud/skills" \
  -H "Authorization: Bearer $QODER_PAT" \
  -F "name=fluxmount" \
  -F "type=custom" \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The guide shows bearer-token usage for Qoder and GitHub APIs without any credential-handling precautions. Users may paste long-lived tokens into shells, logs, screenshots, or shared terminals, increasing the chance of credential leakage and unauthorized access to their accounts or repositories.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · DEPLOY.md (reported line 72)May include surrounding context.

-H "Authorization: Bearer $QODER_PAT"
-F "name=fluxmount"
-F "type=custom"
-F "description=FluxMount - macOS NTFS read-write skill by Changyu Zhang"
-F "file=@fluxmount-qoder.zip"

text

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · DEPLOY.md (reported line 72)May include surrounding context.

-H "Authorization: Bearer $QODER_PAT"
-F "name=fluxmount"
-F "type=custom"
-F "description=FluxMount - macOS NTFS read-write skill by Changyu Zhang"
-F "file=@fluxmount-qoder.zip"

text

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · DEPLOY.md (reported line 76)May include surrounding context.

-F "file=@fluxmount-qoder.zip"

text

- 端点:`https://api.qoder.com/api/v1/cloud/skills`(阿里云版为 `https://api.qoder.com.cn/api/v1/cloud/skills`)
- 成功返回 `201 Created`,含 `id`(如 `skill_019e...`)。
- 绑定到 Agent(可选):
  ```bash

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · DEPLOY.md (reported line 113)May include surrounding context.

也可用 API 一次性设置(需带你的 GitHub PAT):

bash
curl -X PUT "https://api.github.com/repos/hackerFish/fluxmount/topics" \
  -H "Authorization: Bearer $GITHUB_TOKEN" \
  -H "Accept: application/vnd.github+json" \
  -d '{"names":["ntfs","macos","macfuse","ntfs-3g","filesystem","agent-skills","claude-skills","skill","external-drive","hard-drive","read-write","mount","automation","china","hackintosh"]}'

Rp1

Medium
Category
MCP Rug Pull
Confidence
84% confidence
Finding

The onboarding guide tells users to execute npx skills add hackerFish/fluxmount without pinning an exact package version or integrity source. Because npx resolves and executes code from the registry at install time, a compromised, typo-squatted, or newly published package version could run unexpected code on the user's machine.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The onboarding text says WorkBuddy scans SKILL.md and triggers based on description, but the trigger description is broad and underspecified for a skill that performs local system and disk-mount operations. Ambiguous activation criteria increase the chance that routine conversation about NTFS issues invokes a privileged or safety-sensitive workflow without sufficiently informed user intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The example trigger indicates that a vague user request like '帮我装个能读写 NTFS 硬盘的技能' can automatically match and install this skill. In an agent marketplace context, broad install triggers can cause unintended skill acquisition and subsequent execution of a skill capable of changing local mount behavior on external drives.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The conversational example '帮我挂载这个 NTFS 硬盘可读写' is broad for a skill that can alter filesystem mount state on local hardware. In desktop-agent environments, this kind of natural-language trigger can lead to accidental invocation or overbroad matching, especially when users are only seeking advice rather than immediate execution.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file includes an invocation example saying the user can trigger the skill by saying “Mac 怎么写 NTFS”. As documented elsewhere in the file, activation relies on natural-language matching of the description, but the file does not define specific trigger boundaries, allowed phrasings, or negative examples, which can lead to unintended invocation from ordinary discussion about NTFS on Mac.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.