Back to skill

Security audit

Steam Deck Disk

Security checks for vulnerabilities and agentic risk

Overview

This Steam Deck disk skill is related to its stated purpose, but it needs review because it allows unattended broad deletion and privileged persistent system changes that could cause data loss.

Install only if you are comfortable reviewing every cleanup and system-change command before it runs. Disable or ignore the automatic cleanup rules, avoid blanket rm -rf commands, verify backups first, and treat the /var expansion guide as an advanced recovery/maintenance procedure that can affect boot and application state.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:111
Finding

Unattended wildcard deletion can remove active data and recent backups

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 111–120
Vulnerability Type: T09: Insecure Skill Coding Practices
Risk Level: High

Vulnerable Code

bash
rm -rf ~/.cache/*
rm -rf /tmp/*
rm -rf /home/deck/backup-*
npm cache clean --force

Technical Analysis

The Skill classifies these commands as safe cleanup operations and directs the agent to execute them automatically when disk utilization exceeds a configured threshold during the unattended maintenance window.

The commands do not validate file ownership, file age, file type, active use, or expected path resolution before recursively deleting data. In particular:

  • rm -rf /tmp/* can delete sockets, lock files, working files, and other temporary state belonging to active applications or services.
  • rm -rf /home/deck/backup-* deletes every matching path. Although the surrounding documentation says backups should be older than 24 hours, the command contains no age restriction.
  • rm -rf ~/.cache/* can disrupt running applications and may remove application state that is not safely reproducible.
  • Wildcard expansion offers no preview, reclaimed-space estimate, or confirmation checkpoint.
  • If these commands are executed in an elevated context, the scope can extend beyond the intended user session.

The defect is especially significant because the Skill expressly permits unattended execution rather than requiring the user to inspect and approve the deletion candidates.

Attack Path

  1. A monitored partition exceeds the configured automatic-cleanup threshold.
  2. The agent starts the documented cleanup during the unattended maintenance window.
  3. An application has active files in /tmp, or a valid recent backup matches /home/deck/backup-*.
  4. The wildcard commands select those files without checking their age, ownership, or active use.
  5. Recursive deletion removes the selected content without prompting.
  6. Applic ...[truncated 984 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove recursive wildcard deletion from unattended cleanup.
  2. Require explicit user confirmation after displaying every deletion candidate and an estimated amount of recoverable space.
  3. Replace the backup wildcard with a constrained age-aware discovery step, for example:
    bash
    find /home/deck -maxdepth 1 -type d -name 'backup-*' -mtime +1 -print
    
    Delete only the reviewed output in a separate, confirmed operation.
  4. Use the operating system's temporary-file lifecycle mechanism, such as systemd-tmpfiles --clean, instead of deleting all of /tmp.
  5. Do not purge application caches while the corresponding applications are running.
  6. Validate canonical paths, ownership, mount boundaries, and file types before deletion.
  7. Run cleanup with the least-privileged user account possible and never elevate the broad wildcard commands.
  8. Record selected paths and results in an audit log, but do not treat logging as a substitute for confirmation and validation.

T06 · System Persistence

Error
Location
var-expansion-guide.md:43
Finding

Persistent live migration of /var/lib can produce inconsistent service state

Content
View full analysis

Vulnerability Details

File Location: var-expansion-guide.md, lines 43–71
Vulnerability Type: T06: System Persistence, T09: Insecure Skill Coding Practices
Risk Level: High

Vulnerable Code

bash
sudo mkdir -p /home/var-extended/{lib,cache,spool,opt}

sudo systemctl stop systemd-journald

sudo rsync -av /var/lib/ /home/var-extended/lib/
sudo rsync -av /var/cache/ /home/var-extended/cache/

sudo tee /etc/systemd/system/var-lib.mount <<EOF
[Unit]
Description=Bind mount /var/lib to /home

[Mount]
What=/home/var-extended/lib
Where=/var/lib
Type=none
Options=bind

[Install]
WantedBy=multi-user.target
EOF

sudo systemctl daemon-reload
sudo systemctl enable var-lib.mount
sudo systemctl start var-lib.mount

Technical Analysis

The guide copies the live contents of /var/lib and then installs and enables a root-owned systemd mount unit that permanently redirects /var/lib to storage under /home.

Enabling the unit is functionally related to making the selected bind-mount design survive a reboot; no evidence indicates that it is a covert backdoor. Nevertheless, it is a privileged, cross-session system modification with substantial availability and integrity risk.

Only systemd-journald is stopped before the migration. Other services can continue reading and writing databases, package state, container data, or application state under /var/lib while rsync is running. Consequently, the copied tree may combine files from different points in time or omit changes made during the copy.

The procedure also lacks:

  • Identification and shutdown of all writers using /var/lib.
  • An offline or filesystem-snapshot migration process.
  • A second synchronization pass after stopping writers.
  • Integrity, ownership, permission, and free-space validation.
  • Verification that /home is available before dependent services start.
  • Explicit dependency ordering for services that c ...[truncated 2155 chars]
Remediation
View remediation

Remediation Suggestions

  1. Prefer a supported SteamOS partition-management mechanism rather than redirecting all of /var/lib through a custom persistent bind mount.
  2. Clearly label the bind-mount method as an advanced, high-impact procedure rather than a safe default.
  3. Perform the migration from rescue or offline mode. If that is impossible, identify and stop every process writing beneath /var/lib.
  4. Preserve all required metadata and validate ownership, permissions, links, filesystem capacity, and copied contents before activation.
  5. Test the bind mount temporarily before enabling it at boot.
  6. Add appropriate systemd dependency and ordering rules so /home is mounted and verified before var-lib.mount and all dependent services start.
  7. Keep the original data intact until a reboot and service-integrity checks succeed.
  8. Document and test rollback steps, including disabling the unit, unmounting the bind mount, restoring access to the original directory, and restarting affected services.
  9. Verify critical services, package databases, and filesystem state before and after activation.
  10. Require explicit informed user approval immediately before writing to /etc/systemd/system or enabling the persistent unit.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (32)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
93% confidence
Finding

Although this finding duplicates the same command instance, the underlying issue remains valid: a recursive forced delete against a shell-expanded home cache path is destructive and lacks safeguards. The skill context makes it more dangerous because it is framed as routine maintenance suitable for execution by an assistant.

Content

Scanner excerpt · SKILL.md (reported line 31)May include surrounding context.

用户缓存:

bash
rm -rf ~/.cache/*

npm 缓存:

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
93% confidence
Finding

Although this finding duplicates the same command instance, the underlying issue remains valid: a recursive forced delete against a shell-expanded home cache path is destructive and lacks safeguards. The skill context makes it more dangerous because it is framed as routine maintenance suitable for execution by an assistant.

Content

Scanner excerpt · SKILL.md (reported line 31)May include surrounding context.

用户缓存:

bash
rm -rf ~/.cache/*

npm 缓存:

Missing User Warnings

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill authorizes automatic cleanup during a scheduled quiet window based on partition usage thresholds, but the documented actions include destructive deletions and log pruning without a clear, explicit warning about irreversible data loss. In an agent context, this is dangerous because the skill normalizes unattended deletion behavior, increasing the chance that important transient, cached, or miscategorized files are removed without user review.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This section labels multiple irreversible deletion commands as 'safe cleanup' even though they include recursive force deletion of cache, temporary files, and backup paths. Presenting these as safe without an explicit warning or safeguards can mislead an agent or operator into executing destructive actions that may interrupt applications, remove useful recovery artifacts, or delete unexpectedly matched files.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
93% confidence
Finding

This duplicate finding points to the same automatic-cache-deletion command, which is still dangerous because it combines recursive force deletion with unattended execution guidance. The automation context amplifies the likelihood of accidental loss or disruption.

Content

Scanner excerpt · SKILL.md (reported line 128)May include surrounding context.

md
### 安全清理项目
1. ✅ 系统日志:`journalctl --vacuum-size=10M`
2. ✅ 用户缓存:`rm -rf ~/.cache/*`
3. ✅ 临时文件:`rm -rf /tmp/*`
4. ✅ 旧备份:`rm -rf /home/deck/backup-*` (超过 24 小时)
5. ✅ npm 缓存:`npm cache clean --force`

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
93% confidence
Finding

This duplicate finding points to the same automatic-cache-deletion command, which is still dangerous because it combines recursive force deletion with unattended execution guidance. The automation context amplifies the likelihood of accidental loss or disruption.

Content

Scanner excerpt · SKILL.md (reported line 128)May include surrounding context.

md
### 安全清理项目
1. ✅ 系统日志:`journalctl --vacuum-size=10M`
2. ✅ 用户缓存:`rm -rf ~/.cache/*`
3. ✅ 临时文件:`rm -rf /tmp/*`
4. ✅ 旧备份:`rm -rf /home/deck/backup-*` (超过 24 小时)
5. ✅ npm 缓存:`npm cache clean --force`

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
94% confidence
Finding

This duplicate finding reflects the same '/tmp' deletion behavior; the command remains hazardous because it may remove files in use and affect unrelated processes. Broad temporary-directory purges are not reliably safe in an unattended agent workflow.

Content

Scanner excerpt · SKILL.md (reported line 129)May include surrounding context.

md
### 安全清理项目
1. ✅ 系统日志:`journalctl --vacuum-size=10M`
2. ✅ 用户缓存:`rm -rf ~/.cache/*`
3. ✅ 临时文件:`rm -rf /tmp/*`
4. ✅ 旧备份:`rm -rf /home/deck/backup-*` (超过 24 小时)
5. ✅ npm 缓存:`npm cache clean --force`

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
94% confidence
Finding

This duplicate finding reflects the same '/tmp' deletion behavior; the command remains hazardous because it may remove files in use and affect unrelated processes. Broad temporary-directory purges are not reliably safe in an unattended agent workflow.

Content

Scanner excerpt · SKILL.md (reported line 129)May include surrounding context.

md
### 安全清理项目
1. ✅ 系统日志:`journalctl --vacuum-size=10M`
2. ✅ 用户缓存:`rm -rf ~/.cache/*`
3. ✅ 临时文件:`rm -rf /tmp/*`
4. ✅ 旧备份:`rm -rf /home/deck/backup-*` (超过 24 小时)
5. ✅ npm 缓存:`npm cache clean --force`

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
92% confidence
Finding

This duplicate finding refers to the same wildcard backup deletion command, whose risk remains real because recovery files may be destroyed unexpectedly. The use of a shell glob and recursive force deletion is especially unsuitable for automation.

Content

Scanner excerpt · SKILL.md (reported line 130)May include surrounding context.

md
1. ✅ 系统日志:`journalctl --vacuum-size=10M`
2. ✅ 用户缓存:`rm -rf ~/.cache/*`
3. ✅ 临时文件:`rm -rf /tmp/*`
4. ✅ 旧备份:`rm -rf /home/deck/backup-*` (超过 24 小时)
5. ✅ npm 缓存:`npm cache clean --force`

### 禁止删除(保护)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
92% confidence
Finding

This duplicate finding refers to the same wildcard backup deletion command, whose risk remains real because recovery files may be destroyed unexpectedly. The use of a shell glob and recursive force deletion is especially unsuitable for automation.

Content

Scanner excerpt · SKILL.md (reported line 130)May include surrounding context.

md
1. ✅ 系统日志:`journalctl --vacuum-size=10M`
2. ✅ 用户缓存:`rm -rf ~/.cache/*`
3. ✅ 临时文件:`rm -rf /tmp/*`
4. ✅ 旧备份:`rm -rf /home/deck/backup-*` (超过 24 小时)
5. ✅ npm 缓存:`npm cache clean --force`

### 禁止删除(保护)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file forces a single language for description and usage guidance, with no indication that users may choose another language or locale. This can violate language/locale policy where skills should not impose a language without opt-in unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · var-expansion-guide.md (reported line 13)May include surrounding context.

  1. 备份当前状态
bash
sudo sfdisk -d /dev/nvme0n1 > ~/nvme-partitions-backup.txt
  1. 进入桌面模式,关闭所有应用

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · var-expansion-guide.md (reported line 20)May include surrounding context.

  1. 备份当前状态
bash
sudo sfdisk -d /dev/nvme0n1 > ~/nvme-partitions-backup.txt
  1. 进入桌面模式,关闭所有应用

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · var-expansion-guide.md (reported line 21)May include surrounding context.

  1. 备份当前状态
bash
sudo sfdisk -d /dev/nvme0n1 > ~/nvme-partitions-backup.txt
  1. 进入桌面模式,关闭所有应用

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · var-expansion-guide.md (reported line 45)May include surrounding context.

  1. 备份当前状态
bash
sudo sfdisk -d /dev/nvme0n1 > ~/nvme-partitions-backup.txt
  1. 进入桌面模式,关闭所有应用

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · var-expansion-guide.md (reported line 69)May include surrounding context.

  1. 备份当前状态
bash
sudo sfdisk -d /dev/nvme0n1 > ~/nvme-partitions-backup.txt
  1. 进入桌面模式,关闭所有应用

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · var-expansion-guide.md (reported line 80)May include surrounding context.

  1. 备份当前状态
bash
sudo sfdisk -d /dev/nvme0n1 > ~/nvme-partitions-backup.txt
  1. 进入桌面模式,关闭所有应用

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · var-expansion-guide.md (reported line 83)May include surrounding context.

  1. 备份当前状态
bash
sudo sfdisk -d /dev/nvme0n1 > ~/nvme-partitions-backup.txt
  1. 进入桌面模式,关闭所有应用

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

These instructions direct users to unmount and resize live system partitions, including /var, using privileged tools. Mistakes here can corrupt filesystems, make the device unbootable, or destroy user data, and the warning language is not prominent enough relative to the severity of the operation.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
90% confidence
Finding

Unmounting /var with sudo is a high-risk privileged action because /var contains active system state and service data. Running this outside the correct recovery environment can break running services or destabilize the system immediately.

Content

Scanner excerpt · var-expansion-guide.md (reported line 30)May include surrounding context.

  1. 或者使用命令行(高级用户)
bash
# 卸载 /var(需要在救援模式)
sudo umount /var

# 调整分区大小
sudo growpart /dev/nvme0n1 7

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
93% confidence
Finding

growpart modifies partition boundaries on the target disk and can permanently damage the partition layout if used incorrectly. Because the guide names a specific block device and partition with minimal safeguards, an operator can brick the installation or lose data.

Content

Scanner excerpt · var-expansion-guide.md (reported line 33)May include surrounding context.

md
sudo umount /var

# 调整分区大小
sudo growpart /dev/nvme0n1 7

# 调整文件系统
sudo resize2fs /dev/nvme0n1p7

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
90% confidence
Finding

resize2fs on a system partition is a destructive-capable privileged operation if run against the wrong device or at the wrong time. A mismatch between partition and filesystem state can cause corruption and prevent boot.

Content

Scanner excerpt · var-expansion-guide.md (reported line 36)May include surrounding context.

sudo growpart /dev/nvme0n1 7

调整文件系统

sudo resize2fs /dev/nvme0n1p7

text

### 方案 B:创建 systemd mount 覆盖(安全,无需重启)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
86% confidence
Finding

Stopping systemd-journald affects logging availability and may interfere with system observability during a risky migration. While sometimes operationally necessary, instructing users to stop core services without careful safeguards increases the chance of unstable state and harder recovery.

Content

Scanner excerpt · var-expansion-guide.md (reported line 48)May include surrounding context.

md
sudo mkdir -p /home/var-extended/{lib,cache,spool,opt}

# 停止相关服务
sudo systemctl stop systemd-journald

# 移动现有数据
sudo rsync -av /var/lib/ /home/var-extended/lib/

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
89% confidence
Finding

Copying /var/lib with sudo is dangerous because it contains critical package, service, and state data. An incomplete or inconsistent copy can break applications or core OS components once the bind mount is activated.

Content

Scanner excerpt · var-expansion-guide.md (reported line 51)May include surrounding context.

md
sudo systemctl stop systemd-journald

# 移动现有数据
sudo rsync -av /var/lib/ /home/var-extended/lib/
sudo rsync -av /var/cache/ /home/var-extended/cache/

# 创建 systemd mount 单元

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
88% confidence
Finding

Copying /var/cache with sudo is less critical than /var/lib but still can affect package managers or application behavior if permissions and contents are mishandled. In context, it is part of a persistent filesystem redirection workflow that raises operational risk.

Content

Scanner excerpt · var-expansion-guide.md (reported line 52)May include surrounding context.

md
# 移动现有数据
sudo rsync -av /var/lib/ /home/var-extended/lib/
sudo rsync -av /var/cache/ /home/var-extended/cache/

# 创建 systemd mount 单元
sudo tee /etc/systemd/system/var-lib.mount <<EOF

Static analysis

No suspicious patterns detected.