Back to skill

Security audit

TouchBridge — Phone Biometric Auth for Mac

Security checks for vulnerabilities and agentic risk

Overview

This skill has a coherent authentication-helper purpose, but it asks users to install and run unverified code in the macOS sudo/PAM authentication path and documents an auto-approve test mode.

Review this carefully before installing. It modifies the sudo/macOS authentication path and relies on remote GitHub installer or source content that the skill does not verify. Avoid simulator mode on a real machine, verify the package and source independently, inspect privileged scripts before running them, and make sure you have a tested rollback path for PAM changes.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:11
Finding

Unverified Remote Package Executed with Privileged Security Impact

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
references/setup.md:20
Finding

Simulator Mode Automatically Approves Sudo Authentication

Content
View full analysis
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
references/setup.md:11
Finding

Mutable Upstream Installation Scripts Are Executed as Root

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (16)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The document normalizes passwordless sudo approval and 'auto-approved, no password prompt' behavior without clearly explaining the security consequences of replacing local password entry with remote approval logic. In the context of a PAM/sudo integration, this can weaken the trust boundary around privilege escalation and may enable unintended root access if the phone approval flow, pairing, or simulator mode is abused.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: touchbridge
description: Authenticate sudo and macOS system prompts using your phone's biometric (Face ID/fingerprint) instead of typing passwords. Perfect for Mac Mini, Mac Studio, Mac Pro, and MacBook Neo base users without Touch ID.
homepage: https://github.com/HMAKT99/UnTouchID
metadata:
  {

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 46)May include surrounding context.

md
---
name: touchbridge
description: Authenticate sudo and macOS system prompts using your phone's biometric (Face ID/fingerprint) instead of typing passwords. Perfect for Mac Mini, Mac Studio, Mac Pro, and MacBook Neo base users without Touch ID.
homepage: https://github.com/HMAKT99/UnTouchID
metadata:
  {

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill lacks clear invocation boundaries and instead provides broad operational guidance for installing and using a PAM-based authentication tool. Ambiguous activation scope can cause an agent to invoke the skill in situations involving privileged authentication or system configuration without clear user intent, increasing the chance of unsafe assistance around authentication flows.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
84% confidence
Finding

This section states that TouchBridge automatically handles sudo authentication through a PAM module, meaning the skill operates directly in a privileged authentication path. Because PAM changes affect system-wide authorization behavior, guidance that normalizes this flow without strong warnings, scope limits, and validation raises the risk of unsafe privilege escalation assistance or weakened local security.

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

md
3. Check daemon status: `ls ~/Library/Application\ Support/TouchBridge/daemon.sock`.
4. If daemon not running: `touchbridged serve --simulator` (for testing) or `touchbridged serve --web` (for phone auth).

### For sudo commands

TouchBridge automatically handles `sudo` authentication when installed. The PAM module intercepts the auth request and routes it to the daemon, which prompts the user's phone.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
95% confidence
Finding

The documented --simulator mode is an auto-approve authentication path, which effectively bypasses real user verification for privileged prompts during testing. In a skill context, exposing or recommending this mode without strict gating can normalize or automate approval of sensitive actions and weaken authentication protections around sudo and system prompts.

Content

Scanner excerpt · SKILL.md (reported line 50)May include surrounding context.

md
### Modes

- `touchbridged serve --simulator` — auto-approve (testing, no phone needed)
- `touchbridged serve --web` — any phone via browser URL (no app install)
- `touchbridged serve --interactive` — approve/deny in terminal
- `touchbridged serve` — production mode with paired iPhone/Android via BLE

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
86% confidence
Finding

Referencing /etc/pam.d/sudo confirms the skill concerns modification of a core PAM policy file governing sudo authentication. Even though the text says not to modify it directly, the skill still guides users into a high-risk privileged configuration area where mistakes, untrusted installers, or unsafe automation could compromise authentication or lock in insecure behavior.

Content

Scanner excerpt · SKILL.md (reported line 67)May include surrounding context.

md
## Guardrails

- Never type or log the user's macOS password — TouchBridge replaces password entry entirely.
- If `touchbridged` is not running, sudo falls through to password — never block the user.
- The simulator mode (`--simulator`) is for testing only — remind the user to switch to phone auth for real security.
- Never modify `/etc/pam.d/sudo` directly — use the install script which creates backups.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/setup.md (reported line 18)May include surrounding context.

cd UnTouchID cd daemon && swift build -c release && cd .. make -C pam sudo bash scripts/install.sh

text

## Test (no phone needed)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/setup.md (reported line 28)May include surrounding context.

cd UnTouchID cd daemon && swift build -c release && cd .. make -C pam sudo bash scripts/install.sh

text

## Test (no phone needed)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/setup.md (reported line 39)May include surrounding context.

cd UnTouchID cd daemon && swift build -c release && cd .. make -C pam sudo bash scripts/install.sh

text

## Test (no phone needed)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/setup.md (reported line 55)May include surrounding context.

cd UnTouchID cd daemon && swift build -c release && cd .. make -C pam sudo bash scripts/install.sh

text

## Test (no phone needed)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/setup.md (reported line 61)May include surrounding context.

cd UnTouchID cd daemon && swift build -c release && cd .. make -C pam sudo bash scripts/install.sh

text

## Test (no phone needed)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The setup guide instructs users to run a privileged shell installer with sudo, but provides no warning about reviewing the script, verifying provenance, or the fact that it will modify PAM/authentication components. Because this skill alters a sensitive authentication path, executing the installer as root could compromise the host if the script is unsafe or tampered with.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
94% confidence
Finding

The phrase 'Auto-approved, no password prompt' describes autonomous authorization of a sudo request, which is highly sensitive because it removes interactive verification at the moment of privilege escalation. In an auth-related skill, autonomous approval materially increases the chance of unintended or malicious root actions being authorized.

Content

Scanner excerpt · references/setup.md (reported line 29)May include surrounding context.

Terminal 2

sudo echo 'TouchBridge works!'

→ Auto-approved, no password prompt

text

## Use with any phone (no app install)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The web-based approval flow allows sudo authorization through a URL opened on 'any phone' without documenting channel security, phishing/spoofing risks, device trust requirements, or exposure of approval metadata. For an authentication workflow tied to privilege escalation, omission of these warnings can lead users to approve sensitive actions from untrusted devices or networks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The uninstall section tells users to run a root shell script without any caution about reviewing the script or understanding the rollback of PAM/system files. Although uninstall is less risky than install, it still executes arbitrary privileged code and may alter authentication configuration in a way that can break or weaken the system.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.