Security checks for vulnerabilities and agentic risk
Overview
This Steam Deck disk skill is related to its stated purpose, but it needs review because it allows unattended broad deletion and privileged persistent system changes that could cause data loss.
Install only if you are comfortable reviewing every cleanup and system-change command before it runs. Disable or ignore the automatic cleanup rules, avoid blanket rm -rf commands, verify backups first, and treat the /var expansion guide as an advanced recovery/maintenance procedure that can affect boot and application state.
The Skill classifies these commands as safe cleanup operations and directs the agent to execute them automatically when disk utilization exceeds a configured threshold during the unattended maintenance window.
The commands do not validate file ownership, file age, file type, active use, or expected path resolution before recursively deleting data. In particular:
rm -rf /tmp/* can delete sockets, lock files, working files, and other temporary state belonging to active applications or services.
rm -rf /home/deck/backup-* deletes every matching path. Although the surrounding documentation says backups should be older than 24 hours, the command contains no age restriction.
rm -rf ~/.cache/* can disrupt running applications and may remove application state that is not safely reproducible.
Wildcard expansion offers no preview, reclaimed-space estimate, or confirmation checkpoint.
If these commands are executed in an elevated context, the scope can extend beyond the intended user session.
The defect is especially significant because the Skill expressly permits unattended execution rather than requiring the user to inspect and approve the deletion candidates.
Attack Path
A monitored partition exceeds the configured automatic-cleanup threshold.
The agent starts the documented cleanup during the unattended maintenance window.
An application has active files in /tmp, or a valid recent backup matches /home/deck/backup-*.
The wildcard commands select those files without checking their age, ownership, or active use.
Recursive deletion removes the selected content without prompting.
Applic
...[truncated 984 chars]
Remediation
View remediation
Remediation Suggestions
Remove recursive wildcard deletion from unattended cleanup.
Require explicit user confirmation after displaying every deletion candidate and an estimated amount of recoverable space.
Replace the backup wildcard with a constrained age-aware discovery step, for example:
bash
The guide copies the live contents of /var/lib and then installs and enables a root-owned systemd mount unit that permanently redirects /var/lib to storage under /home.
Enabling the unit is functionally related to making the selected bind-mount design survive a reboot; no evidence indicates that it is a covert backdoor. Nevertheless, it is a privileged, cross-session system modification with substantial availability and integrity risk.
Only systemd-journald is stopped before the migration. Other services can continue reading and writing databases, package state, container data, or application state under /var/lib while rsync is running. Consequently, the copied tree may combine files from different points in time or omit changes made during the copy.
The procedure also lacks:
Identification and shutdown of all writers using /var/lib.
An offline or filesystem-snapshot migration process.
A second synchronization pass after stopping writers.
Integrity, ownership, permission, and free-space validation.
Verification that /home is available before dependent services start.
Explicit dependency ordering for services that c
...[truncated 2155 chars]
Remediation
View remediation
Remediation Suggestions
Prefer a supported SteamOS partition-management mechanism rather than redirecting all of /var/lib through a custom persistent bind mount.
Clearly label the bind-mount method as an advanced, high-impact procedure rather than a safe default.
Perform the migration from rescue or offline mode. If that is impossible, identify and stop every process writing beneath /var/lib.
Preserve all required metadata and validate ownership, permissions, links, filesystem capacity, and copied contents before activation.
Test the bind mount temporarily before enabling it at boot.
Add appropriate systemd dependency and ordering rules so /home is mounted and verified before var-lib.mount and all dependent services start.
Keep the original data intact until a reboot and service-integrity checks succeed.
Document and test rollback steps, including disabling the unit, unmounting the bind mount, restoring access to the original directory, and restarting affected services.
Verify critical services, package databases, and filesystem state before and after activation.
Require explicit informed user approval immediately before writing to /etc/systemd/system or enabling the persistent unit.
Although this finding duplicates the same command instance, the underlying issue remains valid: a recursive forced delete against a shell-expanded home cache path is destructive and lacks safeguards. The skill context makes it more dangerous because it is framed as routine maintenance suitable for execution by an assistant.
Content
Scanner excerpt · SKILL.md (reported line 31)May include surrounding context.
用户缓存:
bash
rm -rf ~/.cache/*
npm 缓存:
Tool Parameter Abuse
High
Category
Tool Misuse
Confidence
93% confidence
Finding
Although this finding duplicates the same command instance, the underlying issue remains valid: a recursive forced delete against a shell-expanded home cache path is destructive and lacks safeguards. The skill context makes it more dangerous because it is framed as routine maintenance suitable for execution by an assistant.
Content
Scanner excerpt · SKILL.md (reported line 31)May include surrounding context.
用户缓存:
bash
rm -rf ~/.cache/*
npm 缓存:
Missing User Warnings
High
Category
Not specified by scanner
Confidence
94% confidence
Finding
The skill authorizes automatic cleanup during a scheduled quiet window based on partition usage thresholds, but the documented actions include destructive deletions and log pruning without a clear, explicit warning about irreversible data loss. In an agent context, this is dangerous because the skill normalizes unattended deletion behavior, increasing the chance that important transient, cached, or miscategorized files are removed without user review.
Content
No source excerpt is available for this finding.
Missing User Warnings
High
Category
Not specified by scanner
Confidence
97% confidence
Finding
This section labels multiple irreversible deletion commands as 'safe cleanup' even though they include recursive force deletion of cache, temporary files, and backup paths. Presenting these as safe without an explicit warning or safeguards can mislead an agent or operator into executing destructive actions that may interrupt applications, remove useful recovery artifacts, or delete unexpectedly matched files.
Content
No source excerpt is available for this finding.
Tool Parameter Abuse
High
Category
Tool Misuse
Confidence
93% confidence
Finding
This duplicate finding points to the same automatic-cache-deletion command, which is still dangerous because it combines recursive force deletion with unattended execution guidance. The automation context amplifies the likelihood of accidental loss or disruption.
Content
Scanner excerpt · SKILL.md (reported line 128)May include surrounding context.
This duplicate finding points to the same automatic-cache-deletion command, which is still dangerous because it combines recursive force deletion with unattended execution guidance. The automation context amplifies the likelihood of accidental loss or disruption.
Content
Scanner excerpt · SKILL.md (reported line 128)May include surrounding context.
This duplicate finding reflects the same '/tmp' deletion behavior; the command remains hazardous because it may remove files in use and affect unrelated processes. Broad temporary-directory purges are not reliably safe in an unattended agent workflow.
Content
Scanner excerpt · SKILL.md (reported line 129)May include surrounding context.
This duplicate finding reflects the same '/tmp' deletion behavior; the command remains hazardous because it may remove files in use and affect unrelated processes. Broad temporary-directory purges are not reliably safe in an unattended agent workflow.
Content
Scanner excerpt · SKILL.md (reported line 129)May include surrounding context.
This duplicate finding refers to the same wildcard backup deletion command, whose risk remains real because recovery files may be destroyed unexpectedly. The use of a shell glob and recursive force deletion is especially unsuitable for automation.
Content
Scanner excerpt · SKILL.md (reported line 130)May include surrounding context.
This duplicate finding refers to the same wildcard backup deletion command, whose risk remains real because recovery files may be destroyed unexpectedly. The use of a shell glob and recursive force deletion is especially unsuitable for automation.
Content
Scanner excerpt · SKILL.md (reported line 130)May include surrounding context.
The file forces a single language for description and usage guidance, with no indication that users may choose another language or locale. This can violate language/locale policy where skills should not impose a language without opt-in unless clearly justified as region-specific.
Content
No source excerpt is available for this finding.
Sudo/Root Execution
Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
Content
Scanner excerpt · var-expansion-guide.md (reported line 13)May include surrounding context.
These instructions direct users to unmount and resize live system partitions, including /var, using privileged tools. Mistakes here can corrupt filesystems, make the device unbootable, or destroy user data, and the warning language is not prominent enough relative to the severity of the operation.
Content
No source excerpt is available for this finding.
Sudo/Root Execution
Medium
Category
Privilege Escalation
Confidence
90% confidence
Finding
Unmounting /var with sudo is a high-risk privileged action because /var contains active system state and service data. Running this outside the correct recovery environment can break running services or destabilize the system immediately.
Content
Scanner excerpt · var-expansion-guide.md (reported line 30)May include surrounding context.
growpart modifies partition boundaries on the target disk and can permanently damage the partition layout if used incorrectly. Because the guide names a specific block device and partition with minimal safeguards, an operator can brick the installation or lose data.
Content
Scanner excerpt · var-expansion-guide.md (reported line 33)May include surrounding context.
resize2fs on a system partition is a destructive-capable privileged operation if run against the wrong device or at the wrong time. A mismatch between partition and filesystem state can cause corruption and prevent boot.
Content
Scanner excerpt · var-expansion-guide.md (reported line 36)May include surrounding context.
sudo growpart /dev/nvme0n1 7
调整文件系统
sudo resize2fs /dev/nvme0n1p7
text
### 方案 B:创建 systemd mount 覆盖(安全,无需重启)
Sudo/Root Execution
Medium
Category
Privilege Escalation
Confidence
86% confidence
Finding
Stopping systemd-journald affects logging availability and may interfere with system observability during a risky migration. While sometimes operationally necessary, instructing users to stop core services without careful safeguards increases the chance of unstable state and harder recovery.
Content
Scanner excerpt · var-expansion-guide.md (reported line 48)May include surrounding context.
Copying /var/lib with sudo is dangerous because it contains critical package, service, and state data. An incomplete or inconsistent copy can break applications or core OS components once the bind mount is activated.
Content
Scanner excerpt · var-expansion-guide.md (reported line 51)May include surrounding context.
Copying /var/cache with sudo is less critical than /var/lib but still can affect package managers or application behavior if permissions and contents are mishandled. In context, it is part of a persistent filesystem redirection workflow that raises operational risk.
Content
Scanner excerpt · var-expansion-guide.md (reported line 52)May include surrounding context.