T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:11- Finding
Unverified Remote Package Executed with Privileged Security Impact
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill has a coherent authentication-helper purpose, but it asks users to install and run unverified code in the macOS sudo/PAM authentication path and documents an auto-approve test mode.
Review this carefully before installing. It modifies the sudo/macOS authentication path and relies on remote GitHub installer or source content that the skill does not verify. Avoid simulator mode on a real machine, verify the package and source independently, inspect privileged scripts before running them, and make sure you have a tested rollback path for PAM changes.
SKILL.md:11Unverified Remote Package Executed with Privileged Security Impact
references/setup.md:20Simulator Mode Automatically Approves Sudo Authentication
references/setup.md:11Mutable Upstream Installation Scripts Are Executed as Root
The document normalizes passwordless sudo approval and 'auto-approved, no password prompt' behavior without clearly explaining the security consequences of replacing local password entry with remote approval logic. In the context of a PAM/sudo integration, this can weaken the trust boundary around privilege escalation and may enable unintended root access if the phone approval flow, pairing, or simulator mode is abused.
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
---
name: touchbridge
description: Authenticate sudo and macOS system prompts using your phone's biometric (Face ID/fingerprint) instead of typing passwords. Perfect for Mac Mini, Mac Studio, Mac Pro, and MacBook Neo base users without Touch ID.
homepage: https://github.com/HMAKT99/UnTouchID
metadata:
{
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
---
name: touchbridge
description: Authenticate sudo and macOS system prompts using your phone's biometric (Face ID/fingerprint) instead of typing passwords. Perfect for Mac Mini, Mac Studio, Mac Pro, and MacBook Neo base users without Touch ID.
homepage: https://github.com/HMAKT99/UnTouchID
metadata:
{
The skill lacks clear invocation boundaries and instead provides broad operational guidance for installing and using a PAM-based authentication tool. Ambiguous activation scope can cause an agent to invoke the skill in situations involving privileged authentication or system configuration without clear user intent, increasing the chance of unsafe assistance around authentication flows.
This section states that TouchBridge automatically handles sudo authentication through a PAM module, meaning the skill operates directly in a privileged authentication path. Because PAM changes affect system-wide authorization behavior, guidance that normalizes this flow without strong warnings, scope limits, and validation raises the risk of unsafe privilege escalation assistance or weakened local security.
3. Check daemon status: `ls ~/Library/Application\ Support/TouchBridge/daemon.sock`.
4. If daemon not running: `touchbridged serve --simulator` (for testing) or `touchbridged serve --web` (for phone auth).
### For sudo commands
TouchBridge automatically handles `sudo` authentication when installed. The PAM module intercepts the auth request and routes it to the daemon, which prompts the user's phone.
The documented --simulator mode is an auto-approve authentication path, which effectively bypasses real user verification for privileged prompts during testing. In a skill context, exposing or recommending this mode without strict gating can normalize or automate approval of sensitive actions and weaken authentication protections around sudo and system prompts.
### Modes
- `touchbridged serve --simulator` — auto-approve (testing, no phone needed)
- `touchbridged serve --web` — any phone via browser URL (no app install)
- `touchbridged serve --interactive` — approve/deny in terminal
- `touchbridged serve` — production mode with paired iPhone/Android via BLE
Referencing /etc/pam.d/sudo confirms the skill concerns modification of a core PAM policy file governing sudo authentication. Even though the text says not to modify it directly, the skill still guides users into a high-risk privileged configuration area where mistakes, untrusted installers, or unsafe automation could compromise authentication or lock in insecure behavior.
## Guardrails
- Never type or log the user's macOS password — TouchBridge replaces password entry entirely.
- If `touchbridged` is not running, sudo falls through to password — never block the user.
- The simulator mode (`--simulator`) is for testing only — remind the user to switch to phone auth for real security.
- Never modify `/etc/pam.d/sudo` directly — use the install script which creates backups.
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
cd UnTouchID cd daemon && swift build -c release && cd .. make -C pam sudo bash scripts/install.sh
## Test (no phone needed)
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
cd UnTouchID cd daemon && swift build -c release && cd .. make -C pam sudo bash scripts/install.sh
## Test (no phone needed)
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
cd UnTouchID cd daemon && swift build -c release && cd .. make -C pam sudo bash scripts/install.sh
## Test (no phone needed)
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
cd UnTouchID cd daemon && swift build -c release && cd .. make -C pam sudo bash scripts/install.sh
## Test (no phone needed)
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
cd UnTouchID cd daemon && swift build -c release && cd .. make -C pam sudo bash scripts/install.sh
## Test (no phone needed)
The setup guide instructs users to run a privileged shell installer with sudo, but provides no warning about reviewing the script, verifying provenance, or the fact that it will modify PAM/authentication components. Because this skill alters a sensitive authentication path, executing the installer as root could compromise the host if the script is unsafe or tampered with.
The phrase 'Auto-approved, no password prompt' describes autonomous authorization of a sudo request, which is highly sensitive because it removes interactive verification at the moment of privilege escalation. In an auth-related skill, autonomous approval materially increases the chance of unintended or malicious root actions being authorized.
sudo echo 'TouchBridge works!'
## Use with any phone (no app install)
The web-based approval flow allows sudo authorization through a URL opened on 'any phone' without documenting channel security, phishing/spoofing risks, device trust requirements, or exposure of approval metadata. For an authentication workflow tied to privilege escalation, omission of these warnings can lead users to approve sensitive actions from untrusted devices or networks.
The uninstall section tells users to run a root shell script without any caution about reviewing the script or understanding the rollback of PAM/system files. Although uninstall is less risky than install, it still executes arbitrary privileged code and may alter authentication configuration in a way that can break or weaken the system.
No suspicious patterns detected.