Back to skill

Security audit

Mac Clamshell Mode

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly about Mac power settings as advertised, but its privileged system changes are paired with misleading rollback and safety claims.

Review this before installing if you rely on custom Mac power settings. The skill asks for administrator privileges and can change system-wide sleep behavior; its rollback is not a true backup restore, and some safety options documented in the README are not implemented.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
configure-clamshell.sh:221
Finding

Rollback Overwrites Existing System Power Configuration with Hard-Coded Values

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
configure-clamshell.sh:26
Finding

CPU Architecture Fallback Can Misclassify Unsupported Systems as MacBook Pro Devices

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
test-skill.sh:17
Finding

Advertised Dry-Run and Command-Line Safety Controls Are Not Implemented

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (25)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The code does perform one part of the description: it auto-detects the Mac model and macOS version and evaluates compatibility. However, the declared purpose promises a broader assistant that supports actual lid-closed operation without external peripherals and provides safe configuration with rollback. None of those capabilities are present in the supplied code. The script is only a compatibility checker and does not configure clamshell mode, modify settings, manage peripherals, or implement rollback. Therefore the description materially overstates what the code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description promises a substantive assistant that can enable lid-closed use without external peripherals, auto-detect system compatibility, and configure settings safely with rollback. The actual code shown does none of that; it only echoes a help message. More importantly, the help text contradicts the headline claim by stating that true clamshell mode requires an external display and external keyboard/mouse, and that otherwise the user must rely on separate tools like Amphetamine or caffeinate. This is a material description-versus-behavior mismatch.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest states the skill supports running with the lid closed without an external display/keyboard/mouse, but this README describes conventional clamshell prerequisites such as external power and recommends external display, keyboard, and mouse. Its troubleshooting also assumes an external display is connected, which does not match the broader capability claimed in the manifest.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script's interactive prompts and status messages are presented entirely in Chinese, including confirmation and operational instructions. Under the policy rule for natural-language violations, this is a locale/language constraint without user opt-in or a stated justification that the tool is intended only for Chinese-speaking users.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · configure-clamshell.sh (reported line 20)May include surrounding context.

sh
# Detect Mac model
if command -v system_profiler &> /dev/null; then
    MODEL_IDENTIFIER=$(system_profiler SPHardwareDataType | grep "Model Identifier" | awk '{print $3}' | head -n1)
elif [ -f "/System/Library/CoreServices/PlatformSupport.plist" ]; then
    MODEL_IDENTIFIER=$(defaults read /System/Library/CoreServices/PlatformSupport.plist ModelIdentifier 2>/dev/null || echo "Unknown")
else
    MODEL_IDENTIFIER="Unknown"

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · configure-clamshell.sh (reported line 21)May include surrounding context.

sh
# Detect Mac model
if command -v system_profiler &> /dev/null; then
    MODEL_IDENTIFIER=$(system_profiler SPHardwareDataType | grep "Model Identifier" | awk '{print $3}' | head -n1)
elif [ -f "/System/Library/CoreServices/PlatformSupport.plist" ]; then
    MODEL_IDENTIFIER=$(defaults read /System/Library/CoreServices/PlatformSupport.plist ModelIdentifier 2>/dev/null || echo "Unknown")
else
    MODEL_IDENTIFIER="Unknown"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · configure-clamshell.sh (reported line 102)May include surrounding context.

sh
# Configure for proper clamshell mode
        if [[ $(echo "$MACOS_VERSION" | cut -d. -f1) -ge 13 ]]; then
            sudo pmset -a disablesleep 0
        fi
        sudo pmset -a lidwake 1
        sudo pmset -a acwake 1

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · configure-clamshell.sh (reported line 104)May include surrounding context.

sh
# Configure for proper clamshell mode
        if [[ $(echo "$MACOS_VERSION" | cut -d. -f1) -ge 13 ]]; then
            sudo pmset -a disablesleep 0
        fi
        sudo pmset -a lidwake 1
        sudo pmset -a acwake 1

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · configure-clamshell.sh (reported line 105)May include surrounding context.

sh
# Configure for proper clamshell mode
        if [[ $(echo "$MACOS_VERSION" | cut -d. -f1) -ge 13 ]]; then
            sudo pmset -a disablesleep 0
        fi
        sudo pmset -a lidwake 1
        sudo pmset -a acwake 1

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · configure-clamshell.sh (reported line 141)May include surrounding context.

sh
# Configure for proper clamshell mode
        if [[ $(echo "$MACOS_VERSION" | cut -d. -f1) -ge 13 ]]; then
            sudo pmset -a disablesleep 0
        fi
        sudo pmset -a lidwake 1
        sudo pmset -a acwake 1

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · configure-clamshell.sh (reported line 144)May include surrounding context.

sh
# Configure for proper clamshell mode
        if [[ $(echo "$MACOS_VERSION" | cut -d. -f1) -ge 13 ]]; then
            sudo pmset -a disablesleep 0
        fi
        sudo pmset -a lidwake 1
        sudo pmset -a acwake 1

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · configure-clamshell.sh (reported line 145)May include surrounding context.

sh
# Configure for proper clamshell mode
        if [[ $(echo "$MACOS_VERSION" | cut -d. -f1) -ge 13 ]]; then
            sudo pmset -a disablesleep 0
        fi
        sudo pmset -a lidwake 1
        sudo pmset -a acwake 1

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · configure-clamshell.sh (reported line 146)May include surrounding context.

sh
# Configure for proper clamshell mode
        if [[ $(echo "$MACOS_VERSION" | cut -d. -f1) -ge 13 ]]; then
            sudo pmset -a disablesleep 0
        fi
        sudo pmset -a lidwake 1
        sudo pmset -a acwake 1

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · configure-clamshell.sh (reported line 150)May include surrounding context.

sh
# Configure for proper clamshell mode
        if [[ $(echo "$MACOS_VERSION" | cut -d. -f1) -ge 13 ]]; then
            sudo pmset -a disablesleep 0
        fi
        sudo pmset -a lidwake 1
        sudo pmset -a acwake 1

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · configure-clamshell.sh (reported line 153)May include surrounding context.

sh
# Configure for proper clamshell mode
        if [[ $(echo "$MACOS_VERSION" | cut -d. -f1) -ge 13 ]]; then
            sudo pmset -a disablesleep 0
        fi
        sudo pmset -a lidwake 1
        sudo pmset -a acwake 1

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · configure-clamshell.sh (reported line 166)May include surrounding context.

sh
# Configure for proper clamshell mode
        if [[ $(echo "$MACOS_VERSION" | cut -d. -f1) -ge 13 ]]; then
            sudo pmset -a disablesleep 0
        fi
        sudo pmset -a lidwake 1
        sudo pmset -a acwake 1

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · configure-clamshell.sh (reported line 168)May include surrounding context.

sh
# Configure for proper clamshell mode
        if [[ $(echo "$MACOS_VERSION" | cut -d. -f1) -ge 13 ]]; then
            sudo pmset -a disablesleep 0
        fi
        sudo pmset -a lidwake 1
        sudo pmset -a acwake 1

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · configure-clamshell.sh (reported line 170)May include surrounding context.

sh
# Configure for proper clamshell mode
        if [[ $(echo "$MACOS_VERSION" | cut -d. -f1) -ge 13 ]]; then
            sudo pmset -a disablesleep 0
        fi
        sudo pmset -a lidwake 1
        sudo pmset -a acwake 1

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · configure-clamshell.sh (reported line 224)May include surrounding context.

sh
# Configure for proper clamshell mode
        if [[ $(echo "$MACOS_VERSION" | cut -d. -f1) -ge 13 ]]; then
            sudo pmset -a disablesleep 0
        fi
        sudo pmset -a lidwake 1
        sudo pmset -a acwake 1

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · configure-clamshell.sh (reported line 228)May include surrounding context.

sh
# Configure for proper clamshell mode
        if [[ $(echo "$MACOS_VERSION" | cut -d. -f1) -ge 13 ]]; then
            sudo pmset -a disablesleep 0
        fi
        sudo pmset -a lidwake 1
        sudo pmset -a acwake 1

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · configure-clamshell.sh (reported line 231)May include surrounding context.

sh
# Configure for proper clamshell mode
        if [[ $(echo "$MACOS_VERSION" | cut -d. -f1) -ge 13 ]]; then
            sudo pmset -a disablesleep 0
        fi
        sudo pmset -a lidwake 1
        sudo pmset -a acwake 1

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · configure-clamshell.sh (reported line 234)May include surrounding context.

sh
# Configure for proper clamshell mode
        if [[ $(echo "$MACOS_VERSION" | cut -d. -f1) -ge 13 ]]; then
            sudo pmset -a disablesleep 0
        fi
        sudo pmset -a lidwake 1
        sudo pmset -a acwake 1

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · configure-clamshell.sh (reported line 237)May include surrounding context.

sh
# Configure for proper clamshell mode
        if [[ $(echo "$MACOS_VERSION" | cut -d. -f1) -ge 13 ]]; then
            sudo pmset -a disablesleep 0
        fi
        sudo pmset -a lidwake 1
        sudo pmset -a acwake 1

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script claims to support safe rollback, but its restore path writes hard-coded pmset values instead of restoring the machine’s previously configured settings. This can leave the system in a weaker or unstable power-management state after use, especially on systems with custom enterprise, battery-health, or accessibility-related power policies.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest says the skill supports running with the lid closed without an external display, keyboard, or mouse. However, this help script states that true clamshell mode requires an external display and external keyboard/mouse, and further says that without an external display the user must rely on Amphetamine or caffeinate. This is an active contradiction between the skill's stated intent and its bundled documentation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.