T09 · Insecure Skill Coding Practices
- Location
configure-clamshell.sh:221- Finding
Rollback Overwrites Existing System Power Configuration with Hard-Coded Values
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is mostly about Mac power settings as advertised, but its privileged system changes are paired with misleading rollback and safety claims.
Review this before installing if you rely on custom Mac power settings. The skill asks for administrator privileges and can change system-wide sleep behavior; its rollback is not a true backup restore, and some safety options documented in the README are not implemented.
configure-clamshell.sh:221Rollback Overwrites Existing System Power Configuration with Hard-Coded Values
configure-clamshell.sh:26CPU Architecture Fallback Can Misclassify Unsupported Systems as MacBook Pro Devices
test-skill.sh:17Advertised Dry-Run and Command-Line Safety Controls Are Not Implemented
The code does perform one part of the description: it auto-detects the Mac model and macOS version and evaluates compatibility. However, the declared purpose promises a broader assistant that supports actual lid-closed operation without external peripherals and provides safe configuration with rollback. None of those capabilities are present in the supplied code. The script is only a compatibility checker and does not configure clamshell mode, modify settings, manage peripherals, or implement rollback. Therefore the description materially overstates what the code chunk actually does.
The declared description promises a substantive assistant that can enable lid-closed use without external peripherals, auto-detect system compatibility, and configure settings safely with rollback. The actual code shown does none of that; it only echoes a help message. More importantly, the help text contradicts the headline claim by stating that true clamshell mode requires an external display and external keyboard/mouse, and that otherwise the user must rely on separate tools like Amphetamine or caffeinate. This is a material description-versus-behavior mismatch.
The manifest states the skill supports running with the lid closed without an external display/keyboard/mouse, but this README describes conventional clamshell prerequisites such as external power and recommends external display, keyboard, and mouse. Its troubleshooting also assumes an external display is connected, which does not match the broader capability claimed in the manifest.
The script's interactive prompts and status messages are presented entirely in Chinese, including confirmation and operational instructions. Under the policy rule for natural-language violations, this is a locale/language constraint without user opt-in or a stated justification that the tool is intended only for Chinese-speaking users.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
# Detect Mac model
if command -v system_profiler &> /dev/null; then
MODEL_IDENTIFIER=$(system_profiler SPHardwareDataType | grep "Model Identifier" | awk '{print $3}' | head -n1)
elif [ -f "/System/Library/CoreServices/PlatformSupport.plist" ]; then
MODEL_IDENTIFIER=$(defaults read /System/Library/CoreServices/PlatformSupport.plist ModelIdentifier 2>/dev/null || echo "Unknown")
else
MODEL_IDENTIFIER="Unknown"
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
# Detect Mac model
if command -v system_profiler &> /dev/null; then
MODEL_IDENTIFIER=$(system_profiler SPHardwareDataType | grep "Model Identifier" | awk '{print $3}' | head -n1)
elif [ -f "/System/Library/CoreServices/PlatformSupport.plist" ]; then
MODEL_IDENTIFIER=$(defaults read /System/Library/CoreServices/PlatformSupport.plist ModelIdentifier 2>/dev/null || echo "Unknown")
else
MODEL_IDENTIFIER="Unknown"
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# Configure for proper clamshell mode
if [[ $(echo "$MACOS_VERSION" | cut -d. -f1) -ge 13 ]]; then
sudo pmset -a disablesleep 0
fi
sudo pmset -a lidwake 1
sudo pmset -a acwake 1
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# Configure for proper clamshell mode
if [[ $(echo "$MACOS_VERSION" | cut -d. -f1) -ge 13 ]]; then
sudo pmset -a disablesleep 0
fi
sudo pmset -a lidwake 1
sudo pmset -a acwake 1
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# Configure for proper clamshell mode
if [[ $(echo "$MACOS_VERSION" | cut -d. -f1) -ge 13 ]]; then
sudo pmset -a disablesleep 0
fi
sudo pmset -a lidwake 1
sudo pmset -a acwake 1
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# Configure for proper clamshell mode
if [[ $(echo "$MACOS_VERSION" | cut -d. -f1) -ge 13 ]]; then
sudo pmset -a disablesleep 0
fi
sudo pmset -a lidwake 1
sudo pmset -a acwake 1
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# Configure for proper clamshell mode
if [[ $(echo "$MACOS_VERSION" | cut -d. -f1) -ge 13 ]]; then
sudo pmset -a disablesleep 0
fi
sudo pmset -a lidwake 1
sudo pmset -a acwake 1
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# Configure for proper clamshell mode
if [[ $(echo "$MACOS_VERSION" | cut -d. -f1) -ge 13 ]]; then
sudo pmset -a disablesleep 0
fi
sudo pmset -a lidwake 1
sudo pmset -a acwake 1
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# Configure for proper clamshell mode
if [[ $(echo "$MACOS_VERSION" | cut -d. -f1) -ge 13 ]]; then
sudo pmset -a disablesleep 0
fi
sudo pmset -a lidwake 1
sudo pmset -a acwake 1
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# Configure for proper clamshell mode
if [[ $(echo "$MACOS_VERSION" | cut -d. -f1) -ge 13 ]]; then
sudo pmset -a disablesleep 0
fi
sudo pmset -a lidwake 1
sudo pmset -a acwake 1
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# Configure for proper clamshell mode
if [[ $(echo "$MACOS_VERSION" | cut -d. -f1) -ge 13 ]]; then
sudo pmset -a disablesleep 0
fi
sudo pmset -a lidwake 1
sudo pmset -a acwake 1
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# Configure for proper clamshell mode
if [[ $(echo "$MACOS_VERSION" | cut -d. -f1) -ge 13 ]]; then
sudo pmset -a disablesleep 0
fi
sudo pmset -a lidwake 1
sudo pmset -a acwake 1
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# Configure for proper clamshell mode
if [[ $(echo "$MACOS_VERSION" | cut -d. -f1) -ge 13 ]]; then
sudo pmset -a disablesleep 0
fi
sudo pmset -a lidwake 1
sudo pmset -a acwake 1
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# Configure for proper clamshell mode
if [[ $(echo "$MACOS_VERSION" | cut -d. -f1) -ge 13 ]]; then
sudo pmset -a disablesleep 0
fi
sudo pmset -a lidwake 1
sudo pmset -a acwake 1
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# Configure for proper clamshell mode
if [[ $(echo "$MACOS_VERSION" | cut -d. -f1) -ge 13 ]]; then
sudo pmset -a disablesleep 0
fi
sudo pmset -a lidwake 1
sudo pmset -a acwake 1
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# Configure for proper clamshell mode
if [[ $(echo "$MACOS_VERSION" | cut -d. -f1) -ge 13 ]]; then
sudo pmset -a disablesleep 0
fi
sudo pmset -a lidwake 1
sudo pmset -a acwake 1
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# Configure for proper clamshell mode
if [[ $(echo "$MACOS_VERSION" | cut -d. -f1) -ge 13 ]]; then
sudo pmset -a disablesleep 0
fi
sudo pmset -a lidwake 1
sudo pmset -a acwake 1
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# Configure for proper clamshell mode
if [[ $(echo "$MACOS_VERSION" | cut -d. -f1) -ge 13 ]]; then
sudo pmset -a disablesleep 0
fi
sudo pmset -a lidwake 1
sudo pmset -a acwake 1
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# Configure for proper clamshell mode
if [[ $(echo "$MACOS_VERSION" | cut -d. -f1) -ge 13 ]]; then
sudo pmset -a disablesleep 0
fi
sudo pmset -a lidwake 1
sudo pmset -a acwake 1
The script claims to support safe rollback, but its restore path writes hard-coded pmset values instead of restoring the machine’s previously configured settings. This can leave the system in a weaker or unstable power-management state after use, especially on systems with custom enterprise, battery-health, or accessibility-related power policies.
The manifest says the skill supports running with the lid closed without an external display, keyboard, or mouse. However, this help script states that true clamshell mode requires an external display and external keyboard/mouse, and further says that without an external display the user must rely on Amphetamine or caffeinate. This is an active contradiction between the skill's stated intent and its bundled documentation.
No suspicious patterns detected.