Back to skill

Security audit

Termux Persistent Gateway

Security checks for vulnerabilities and agentic risk

Overview

The skill openly helps keep a Termux gateway running in the background, including optional boot and cron persistence, and I found no hidden payload or exfiltration.

Install this only if you want a trusted gateway to keep running on an Android/Termux device. Review the GATEWAY_CMD and script paths before enabling boot or cron persistence, restrict network exposure, monitor logs and resource use, and know how to disable it by removing the Termux:Boot script, deleting the cron entry, killing the tmux session, and releasing the wake-lock.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T06 · System Persistence

Error
Location
templates/termux-boot.sh:2
Finding

Gateway Execution Persisted Through Termux:Boot

Content
View full analysis

Vulnerability Details

File Location: templates/termux-boot.sh:2-16; installation instructions in SKILL.md:1
Vulnerability Type: T06: System Persistence
Risk Level: High

Vulnerable Code

bash
# Auto-start AI Agent Gateway on device boot
# Install: copy to ~/.termux/boot/agent-gateway and chmod +x
# Adjust SCRIPT path below to match your setup

# Wait for Wi-Fi to connect
sleep 15

# Source profile for PATH + venv
source /data/data/com.termux/files/home/.profile 2>/dev/null || true

# === CONFIG: point this to your run-gateway.sh ===
SCRIPT="/data/data/com.termux/files/home/.agent/scripts/run-gateway.sh"
# =================================================

bash "$SCRIPT"

The installation instructions in SKILL.md:1 direct the user to register this script with Termux:Boot:

bash
mkdir -p ~/.termux/boot/
cp [skill_dir]/templates/termux-boot.sh ~/.termux/boot/agent-gateway
chmod +x ~/.termux/boot/agent-gateway

Technical Analysis

The Skill instructs the user to install an executable in ~/.termux/boot/, causing it to run after every device reboot. After a fixed delay, the boot hook sources the user's complete .profile and launches a configured gateway script.

This persistence is explicitly disclosed and directly supports the declared persistent-gateway functionality. It is not covert. Nevertheless, it survives the original Skill invocation and automatically executes local content in future sessions, meeting the definition of system persistence.

Sourcing the complete .profile expands the trust boundary unnecessarily. Any command subsequently added to or injected into .profile will execute during boot. The configured launcher is also referenced through a writable path under the Termux home directory, so later compromise of that file can turn the legitimate boot hook into an automatic execution mechanism.

Attack Path

  1. The user follows SKILL.md:1 and ...[truncated 1315 chars]
Remediation
View remediation

Remediation Suggestions

  • Keep boot persistence strictly opt-in and separate it from ordinary gateway startup.
  • Display an explicit warning before installation describing boot-time execution, resource consumption, and the permissions inherited from Termux.
  • Do not source the complete user .profile. Define a minimal fixed PATH and any required environment variables directly in the boot script.
  • Resolve and validate an absolute launcher path during installation.
  • Ensure the launcher and boot script are owned and writable only by the Termux user; recommend restrictive permissions such as chmod 700.
  • Validate that the configured launcher is a regular file and not an unexpected symbolic link before executing it.
  • Provide complete removal instructions, including:
    bash
    rm -f ~/.termux/boot/agent-gateway
    tmux kill-session -t agent-gw
    termux-wake-unlock
    
  • Document a nonpersistent mode that launches the gateway manually without Termux:Boot or unrestricted battery access.

T06 · System Persistence

Error
Location
SKILL.md:1
Finding

Scheduled Health Check Automatically Reestablishes Gateway Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:1; restart implementation in scripts/healthcheck.sh:5-20
Vulnerability Type: T06: System Persistence
Risk Level: High

Vulnerable Code

SKILL.md:1 recommends installing the health check as a recurring cron task:

bash
crontab -e
# Add:
*/30 * * * * bash ~/.agent/scripts/healthcheck.sh

The scheduled script automatically executes the configured launcher whenever the named tmux session is absent:

bash
# === CONFIG ===
SESSION_NAME="agent-gw"
LOG_DIR="$HOME/.agent/logs"
SCRIPT_PATH="$HOME/.agent/scripts/run-gateway.sh"
# ===============

mkdir -p "$LOG_DIR"
LOG="$LOG_DIR/healthcheck.log"

if ! tmux has-session -t "$SESSION_NAME" 2>/dev/null; then
  echo "[$(date)] ⚠️ Gateway down! Restarting..." >> "$LOG"
  bash "$SCRIPT_PATH" >> "$LOG" 2>&1
  echo "[$(date)] ✅ Restart done." >> "$LOG"
else
  echo "[$(date)] ✅ Gateway is alive." >> "$LOG"
fi

Technical Analysis

The documented cron entry invokes healthcheck.sh every 30 minutes. The script treats the absence of a tmux session as a failure and executes the configured launcher without verifying its ownership, integrity, expected file type, or contents.

This behavior is disclosed and is relevant to the advertised auto-restart feature. However, it creates a scheduled cross-session execution hook and automatically reestablishes the gateway after it terminates. A later modification of ~/.agent/scripts/run-gateway.sh will be executed by cron when the session is absent.

The check only confirms that a tmux session with the configured name exists. It does not verify that the intended gateway process is healthy, that its network endpoint is safe, or that the launcher completed successfully. The script logs “Restart done” regardless of the launcher's exit status, which can conceal repeated failures.

Attack Path

  1. The user adds the documented entry to the Ter ...[truncated 1223 chars]
Remediation
View remediation

Remediation Suggestions

  • Make cron registration an explicit, separately confirmed option rather than part of the normal setup path.
  • Provide an installer and uninstaller that add and remove only the Skill's exact crontab entry without overwriting unrelated entries.
  • Before executing SCRIPT_PATH, verify that it is a regular file, is not a symbolic link, has expected ownership and permissions, and is not writable by untrusted users.
  • Use an absolute Bash path and a minimal fixed environment under cron.
  • Prefer a direct process-health or authenticated endpoint check instead of relying only on the existence of a tmux session.
  • Check and log the launcher's exit status. Do not report success unconditionally.
  • Add restart throttling, a maximum retry count, and log rotation to prevent resource exhaustion.
  • Document how to disable the scheduled persistence, for example:
    bash
    crontab -e
    # Remove the healthcheck.sh entry.
    
  • Release the wake lock and stop the tmux session when persistence is disabled.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · SKILL.md (reported line 1)May include surrounding context.

md
nt-gateway ``` Edit `~/.termux/boot/agent-gateway` to point `SCRIPT` at your `run-gateway.sh` path. The `sleep 15` gives Wi-Fi time to connect. Now the gateway auto-starts every time you reboot your phone. ## Health Monitoring (Cron) Optional: check on the gateway periodically and restart if it's down. ```bash bash <skill_dir>/scripts/healthcheck.sh ``` To schedule it, add to Termux cron: ```bash crontab -e # Add: */30 * * * * bash ~/.agent/scripts/healthcheck.sh ``` Or use your agent's cron system to run the healthcheck every 30 minutes. ## Verify It's Working ```bash # Check gateway is running tmux ls # Should show: agent-gw: 1 windows (created ...) # Check wake-lock is held termux-wake-lock 2>/dev/null || echo "wake-lock not acquired (probably already held)" ``` ## Troubleshooting | Problem | Fix | |---------|-----| | Gateway dies after screen off | Set Termux battery to **Unrestricted** | | Gateway dies after app close | Don't force-close Termux. Just swipe it away — tmux keeps r

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README explicitly promotes persistent execution, wake locks, and auto-start on boot on a mobile device, but it does not warn users about battery drain, thermal impact, background resource consumption, or increased exposure from keeping a gateway continuously available. While this is not direct code execution or malware behavior by itself, omitting these operational risks can mislead users into deploying a long-running network-facing service in a way that weakens device safety and reliability.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
92% confidence
Finding

Installing Termux:Boot, creating a script under ~/.termux/boot/, and instructing the user to make it executable creates automatic execution on device reboot. Auto-execution is a meaningful persistence mechanism; in a benign admin skill this is contextualized, but it remains dangerous if pointed at an unsafe script or reused by another actor on the device.

Content

Scanner excerpt · SKILL.md (reported line 1)May include surrounding context.

md
--- name: termux-persistent-gateway description: "Keep an AI agent gateway running persistently on Android/Termux — tmux + wake-lock + auto-start on boot + health monitor. No systemd needed. Use when: (1) running a gateway on Termux/Android, (2) making gateway survive screen-off or reboots, (3) setting up auto-restart health monitoring on Termux." version: 1.1.0 author: kingofqin2026 license: MIT tags: [termux, android, gateway, persistent, tmux, wake-lock, auto-start] --- # Termux Persistent Gateway Keep your AI agent gateway alive on Android (no systemd), surviving screen-off, app-switching, and device reboots. ## Prerequisites ```bash pkg install tmux termux-api termux-boot ``` - **tmux** — terminal multiplexer, keeps the session alive when you close Termux - **termux-api** — provides `termux-wake-lock` / `termux-notification` - **termux-boot** — auto-start on device boot - **Android setting**: Settings > Apps > Termux > Battery > **Unrestricted** (critical — prevents Android from killing Termux) ## Configuration Before first use, edit the scripts to set: - **`GATEWAY_CMD`** — the command that starts your gateway (e.g. `openclaw gateway run`, `hermes gateway run`) - **`SESSION_NAME`** — the tmux session name (default: `agent-gw`) - **`LOG_DIR`** — where logs are stored (default: `~/.agent/logs`) All configurable values are at the top of each script — look for the `# === CONFIG ===` block. ## Quick Start ### Start the gateway ```bash bash <skill_dir>/scripts/run-gateway.sh ``` This script: 1. Acquires a wake lock (`termux-wake-lock`) so CPU stays alive 2. Kills any old gateway tmux session 3. Starts your gateway command inside a new tmux session 4. Logs output to the configured log directory ### Manage the session | Action | Command | |--------|---------| | Attach (see live output) | `tmux attach -t agent-gw` | | Detach | `Ctrl+B, D` | | Check if running | `tmux ls` | | View recent logs | `tail -f ~/.agent/logs/gateway-termux.log` | | Restart | kill session + run 
...[truncated 26 chars]

Session Persistence

Medium
Category
Rogue Agent
Confidence
92% confidence
Finding

Installing Termux:Boot, creating a script under ~/.termux/boot/, and instructing the user to make it executable creates automatic execution on device reboot. Auto-execution is a meaningful persistence mechanism; in a benign admin skill this is contextualized, but it remains dangerous if pointed at an unsafe script or reused by another actor on the device.

Content

Scanner excerpt · SKILL.md (reported line 1)May include surrounding context.

md
--- name: termux-persistent-gateway description: "Keep an AI agent gateway running persistently on Android/Termux — tmux + wake-lock + auto-start on boot + health monitor. No systemd needed. Use when: (1) running a gateway on Termux/Android, (2) making gateway survive screen-off or reboots, (3) setting up auto-restart health monitoring on Termux." version: 1.1.0 author: kingofqin2026 license: MIT tags: [termux, android, gateway, persistent, tmux, wake-lock, auto-start] --- # Termux Persistent Gateway Keep your AI agent gateway alive on Android (no systemd), surviving screen-off, app-switching, and device reboots. ## Prerequisites ```bash pkg install tmux termux-api termux-boot ``` - **tmux** — terminal multiplexer, keeps the session alive when you close Termux - **termux-api** — provides `termux-wake-lock` / `termux-notification` - **termux-boot** — auto-start on device boot - **Android setting**: Settings > Apps > Termux > Battery > **Unrestricted** (critical — prevents Android from killing Termux) ## Configuration Before first use, edit the scripts to set: - **`GATEWAY_CMD`** — the command that starts your gateway (e.g. `openclaw gateway run`, `hermes gateway run`) - **`SESSION_NAME`** — the tmux session name (default: `agent-gw`) - **`LOG_DIR`** — where logs are stored (default: `~/.agent/logs`) All configurable values are at the top of each script — look for the `# === CONFIG ===` block. ## Quick Start ### Start the gateway ```bash bash <skill_dir>/scripts/run-gateway.sh ``` This script: 1. Acquires a wake lock (`termux-wake-lock`) so CPU stays alive 2. Kills any old gateway tmux session 3. Starts your gateway command inside a new tmux session 4. Logs output to the configured log directory ### Manage the session | Action | Command | |--------|---------| | Attach (see live output) | `tmux attach -t agent-gw` | | Detach | `Ctrl+B, D` | | Check if running | `tmux ls` | | View recent logs | `tail -f ~/.agent/logs/gateway-termux.log` | | Restart | kill session + run 
...[truncated 26 chars]

Session Persistence

Medium
Category
Rogue Agent
Confidence
92% confidence
Finding

Installing Termux:Boot, creating a script under ~/.termux/boot/, and instructing the user to make it executable creates automatic execution on device reboot. Auto-execution is a meaningful persistence mechanism; in a benign admin skill this is contextualized, but it remains dangerous if pointed at an unsafe script or reused by another actor on the device.

Content

Scanner excerpt · SKILL.md (reported line 1)May include surrounding context.

md
--- name: termux-persistent-gateway description: "Keep an AI agent gateway running persistently on Android/Termux — tmux + wake-lock + auto-start on boot + health monitor. No systemd needed. Use when: (1) running a gateway on Termux/Android, (2) making gateway survive screen-off or reboots, (3) setting up auto-restart health monitoring on Termux." version: 1.1.0 author: kingofqin2026 license: MIT tags: [termux, android, gateway, persistent, tmux, wake-lock, auto-start] --- # Termux Persistent Gateway Keep your AI agent gateway alive on Android (no systemd), surviving screen-off, app-switching, and device reboots. ## Prerequisites ```bash pkg install tmux termux-api termux-boot ``` - **tmux** — terminal multiplexer, keeps the session alive when you close Termux - **termux-api** — provides `termux-wake-lock` / `termux-notification` - **termux-boot** — auto-start on device boot - **Android setting**: Settings > Apps > Termux > Battery > **Unrestricted** (critical — prevents Android from killing Termux) ## Configuration Before first use, edit the scripts to set: - **`GATEWAY_CMD`** — the command that starts your gateway (e.g. `openclaw gateway run`, `hermes gateway run`) - **`SESSION_NAME`** — the tmux session name (default: `agent-gw`) - **`LOG_DIR`** — where logs are stored (default: `~/.agent/logs`) All configurable values are at the top of each script — look for the `# === CONFIG ===` block. ## Quick Start ### Start the gateway ```bash bash <skill_dir>/scripts/run-gateway.sh ``` This script: 1. Acquires a wake lock (`termux-wake-lock`) so CPU stays alive 2. Kills any old gateway tmux session 3. Starts your gateway command inside a new tmux session 4. Logs output to the configured log directory ### Manage the session | Action | Command | |--------|---------| | Attach (see live output) | `tmux attach -t agent-gw` | | Detach | `Ctrl+B, D` | | Check if running | `tmux ls` | | View recent logs | `tail -f ~/.agent/logs/gateway-termux.log` | | Restart | kill session + run 
...[truncated 26 chars]

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The skill prominently instructs users to enable persistent background execution via wake-locks, unrestricted battery settings, tmux persistence, boot auto-start, and periodic health checks, but it does not present an explicit warning about the battery, privacy, and operational consequences of keeping a gateway continuously running. In a persistence-focused skill, omission of that warning increases the chance of unsafe or unintended deployment even if the behavior is intentional.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.