T06 · System Persistence
- Location
templates/termux-boot.sh:2- Finding
Gateway Execution Persisted Through Termux:Boot
- Content
View full analysis
Vulnerability Details
File Location:
templates/termux-boot.sh:2-16; installation instructions inSKILL.md:1
Vulnerability Type: T06: System Persistence
Risk Level: HighVulnerable Code
bash # Auto-start AI Agent Gateway on device boot # Install: copy to ~/.termux/boot/agent-gateway and chmod +x # Adjust SCRIPT path below to match your setup # Wait for Wi-Fi to connect sleep 15 # Source profile for PATH + venv source /data/data/com.termux/files/home/.profile 2>/dev/null || true # === CONFIG: point this to your run-gateway.sh === SCRIPT="/data/data/com.termux/files/home/.agent/scripts/run-gateway.sh" # ================================================= bash "$SCRIPT"The installation instructions in
SKILL.md:1direct the user to register this script with Termux:Boot:bash mkdir -p ~/.termux/boot/ cp [skill_dir]/templates/termux-boot.sh ~/.termux/boot/agent-gateway chmod +x ~/.termux/boot/agent-gatewayTechnical Analysis
The Skill instructs the user to install an executable in
~/.termux/boot/, causing it to run after every device reboot. After a fixed delay, the boot hook sources the user's complete.profileand launches a configured gateway script.This persistence is explicitly disclosed and directly supports the declared persistent-gateway functionality. It is not covert. Nevertheless, it survives the original Skill invocation and automatically executes local content in future sessions, meeting the definition of system persistence.
Sourcing the complete
.profileexpands the trust boundary unnecessarily. Any command subsequently added to or injected into.profilewill execute during boot. The configured launcher is also referenced through a writable path under the Termux home directory, so later compromise of that file can turn the legitimate boot hook into an automatic execution mechanism.Attack Path
- The user follows
SKILL.md:1and ...[truncated 1315 chars]
- The user follows
- Remediation
View remediation
Remediation Suggestions
- Keep boot persistence strictly opt-in and separate it from ordinary gateway startup.
- Display an explicit warning before installation describing boot-time execution, resource consumption, and the permissions inherited from Termux.
- Do not source the complete user
.profile. Define a minimal fixedPATHand any required environment variables directly in the boot script. - Resolve and validate an absolute launcher path during installation.
- Ensure the launcher and boot script are owned and writable only by the Termux user; recommend restrictive permissions such as
chmod 700. - Validate that the configured launcher is a regular file and not an unexpected symbolic link before executing it.
- Provide complete removal instructions, including:
bash rm -f ~/.termux/boot/agent-gateway tmux kill-session -t agent-gw termux-wake-unlock - Document a nonpersistent mode that launches the gateway manually without Termux:Boot or unrestricted battery access.
