Back to skill

Security audit

workbuddy-icloud-sync

Security checks for vulnerabilities and agentic risk

Overview

The skill has a legitimate iCloud sync purpose, but it installs persistent background syncing and can overwrite or silently propagate WorkBuddy configuration and skills without enough user control.

Review this before installing. It may be acceptable if you intentionally want automatic WorkBuddy sync across trusted Macs on the same iCloud account, but run it only after backing up ~/.workbuddy and reviewing the shell profile changes. Be aware it can overwrite local WorkBuddy changes, alter global Git settings, sync unintended unignored files, and keep running background sync code until you remove the profile hook and daemon state.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/auto-sync-icloud.sh:31
Finding

Blanket Git Staging Can Synchronize Undeclared Sensitive Files

Content
View full analysis
/dev/null 2>&1 # 2. Commit local changes (skip if nothing staged) git add -A if ! git diff --cached --quiet 2>/dev/null; then git commit -m "auto-sync ${TS} from $(hostname)" >/dev/null 2>&1 fi # 3. Push git push "$REMOTE" "$BRANCH" >/dev/null 2>&1 ``` ### Technical Analysis The recurring synchronization process uses `git add -A`, which stages every unignored file under `~/.workbuddy`. The provided `.gitignore` excludes several known credential and runtime locations, but it is a denylist and does not protect arbitrary sensitive files, newly introduced WorkBuddy paths, private keys, environment files, token exports, or backups that do not match an existing rule. This behavior is broader than the Skill's documented synchronization scope, which identifies a limited set of identity, memory, configuration, and skill files. Any unignored content is automatically committed and copied to the iCloud bare repository. ### Attack Path 1. A user, plugin, tool, or future WorkBuddy version creates a sensitive file under `~/.workbuddy`. 2. The path is not covered by `references/gitignore-template`. 3. The background daemon invokes `auto-sync-icloud.sh`. 4. `git add -A` stages the sensitive file. 5. The script commits it without user review. 6. `git push` copies it into the iCloud Drive bare repository. 7. iCloud and Git propagate the file to other Macs connected to the repository. ### Impact Assessment The issue does not grant elevated system privileges, but it can disclose data accessible to the current user. Exposure is scoped to the user's iCloud account, the bare repository, and every Mac configured to consume that repository. Depending on the ...[truncated 132 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/setup-mac-b-icloud.sh:64
Finding

Mac B Setup Forcefully Replaces Local Git State Without a Complete Backup

Content
View full analysis
> Git repo exists, switching remote to iCloud..." git remote remove "$REMOTE_NAME" 2>/dev/null || true git remote remove origin 2>/dev/null || true git remote add "$REMOTE_NAME" "$BARE_REPO" git fetch "$REMOTE_NAME" git reset --hard "$REMOTE_NAME/$BRANCH" else echo ">> Initializing git and pulling from iCloud..." git init git remote add "$REMOTE_NAME" "$BARE_REPO" git fetch "$REMOTE_NAME" git checkout -f -B "$BRANCH" "$REMOTE_NAME/$BRANCH" fi ``` ### Technical Analysis When `~/.workbuddy` is already a Git repository, setup removes both the existing `icloud` remote and an unrelated `origin` remote. It then executes `git reset --hard` against the iCloud branch. For a newly initialized repository, it uses a forced checkout. These operations can discard tracked local changes and disconnect an existing repository from its configured upstream. The preceding backup routine only copies a fixed subset of paths—`SOUL.md`, `IDENTITY.md`, `USER.md`, `MEMORY.md`, `mcp.json`, `settings.json`, and `skills`—rather than preserving the complete working tree, Git metadata, remote configuration, and all uncommitted content. ### Attack Path 1. Mac B already has a Git repository in `~/.workbuddy`, an `origin` remote, or uncommitted tracked changes. 2. The user runs the one-click setup script. 3. The script removes the existing `origin` remote without preserving its configuration. 4. The script fetches the iCloud repository. 5. `git reset --hard` or `git checkout -f` replaces tracked local files with the remote branch state. 6. Any affected file outside the limited backup set cannot be restored from the setup backup. If the iCloud repository contains incorrect or attacker-modified content, the same forced repl ...[truncated 453 chars]
Remediation
View remediation

T06 · System Persistence

Warning
Location
scripts/setup-mac-b-icloud.sh:92
Finding

Shell Startup Persistence Executes Mutable Synchronized Scripts Without Integrity Validation

Content
View full analysis
/dev/null; then echo ">> Aliases already present, skipping" else cat >> "$PROFILE" << 'PROFILE_EOF' # WorkBuddy iCloud sync shortcuts alias wbsync='cd ~/.workbuddy && git add -A && git commit -m "sync $(date +%m%d-%H%M)" && git push icloud main' alias wbpull='cd ~/.workbuddy && git pull icloud main' # WorkBuddy auto-sync — daemon keepalive + sync on terminal open if [ -f ~/.workbuddy/start-sync-daemon.sh ]; then bash ~/.workbuddy/start-sync-daemon.sh 2>/dev/null fi if [ -t 1 ] && [ -f ~/.workbuddy/auto-sync.sh ]; then _wb_now=$(date +%s) _wb_last=$(cat ~/.workbuddy/.last-auto-sync 2>/dev/null || echo 0) if [ $((_wb_now - _wb_last)) -gt 300 ]; then bash ~/.workbuddy/auto-sync.sh >/dev/null 2>&1 & echo $_wb_now > ~/.workbuddy/.last-auto-sync fi unset _wb_now _wb_last fi PROFILE_EOF ``` ### Technical Analysis The installer permanently appends commands to `.bash_profile` or `.zshrc`. Future shell sessions execute `start-sync-daemon.sh` and `auto-sync.sh` from the user-writable `~/.workbuddy` directory. Automatic background execution is relevant to the declared five-minute synchronization feature and is disclosed to the user. However, the implementation executes mutable files without validating ownership, permissions, content hashes, signatures, or whether the paths are symbolic links. In particular, `auto-sync.sh` is not excluded by the supplied Git ignore template, allowing synchronized repository content to change code that will subsequently execute from the shell startup hook. This creates a cross-session and potentially cross-device code-execution trust boundary. The persistence is user-level rather than a privileged system ...[truncated 1200 chars]
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (17)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 22)May include surrounding context.

md
|--------|-------------|-------------|
| Account needed | iCloud (Apple ID) | GitHub account |
| Network | Apple iCloud (may be slow in China) | GitHub (may need proxy in China) |
| Token/SSH | Not needed | Personal Access Token or SSH key |
| Setup complexity | Very simple | Medium |
| Version history | Yes (git log) | Yes (git log) |
| Best for | Same Apple ID on all Macs | Different accounts or cross-platform |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

git reset --hard icloud/main is a destructive command that discards local changes and blindly trusts the remote repository state. In this skill, that danger is amplified because the remote lives in a sync folder and the same scripts are propagated across machines, so a bad or tampered remote state could overwrite local configuration everywhere.

Content

Scanner excerpt · SKILL.md (reported line 172)May include surrounding context.

md
git remote remove icloud 2>/dev/null
  git remote add icloud "$ICLOUD_DIR/WorkBuddy-sync.git"
  git fetch icloud
  git reset --hard icloud/main
else
  git init
  git remote add icloud "$ICLOUD_DIR/WorkBuddy-sync.git"

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script performs automatic pull, add, commit, and push operations every 5 minutes while suppressing all output and user prompts. Even though the remote is iCloud-backed rather than a traditional network service, this still silently propagates local file changes and ingests remote changes into a sensitive config directory, which can overwrite configuration, spread mistakes across devices, and reduce user awareness of repository activity.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

git reset --hard forcibly replaces the working tree with the remote branch, destroying any local uncommitted changes in ~/.workbuddy. Although the script backs up some named files earlier, the reset still performs a destructive overwrite without an explicit confirmation and may discard files or state not covered by the backup logic.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
92% confidence
Finding

The use of git reset --hard is a dangerous tool invocation because it irreversibly discards local modifications in the target repository. In a one-click setup script, this can be triggered without the user's full awareness, and the iCloud-sync context makes the local state subordinate to whatever is present in the synced bare repository.

Content

Scanner excerpt · scripts/setup-mac-b-icloud.sh (reported line 71)May include surrounding context.

sh
git remote remove origin 2>/dev/null || true
  git remote add "$REMOTE_NAME" "$BARE_REPO"
  git fetch "$REMOTE_NAME"
  git reset --hard "$REMOTE_NAME/$BRANCH"
else
  echo ">> Initializing git and pulling from iCloud..."
  git init

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill provides shell commands that write files, modify shell startup files, start background processes, and reconfigure Git, but it declares no explicit tool scope or permissions boundary. In an agent setting, that mismatch increases the chance that an assistant could perform filesystem and shell actions without clear user-visible authorization.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 72)May include surrounding context.

git init

text

#### Step 3: Create `.gitignore`

Copy `references/gitignore-template` to `~/.workbuddy/.gitignore`.
This excludes all machine-specific files (binaries, workbuddy.db, .mcp.json,

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The Mac B setup uses git reset --hard icloud/main and forceful checkout behavior that can overwrite an existing ~/.workbuddy state. Although a partial backup is attempted only when SOUL.md exists, the instructions do not prominently warn that local uncommitted changes and some existing configuration may be destroyed.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
88% confidence
Finding

The skill sets up a background daemon that restarts sync activity periodically and on terminal open, creating persistent execution on the host. In a configuration-sync skill, persistent shell-based background execution broadens attack surface because any later tampering with the synced scripts could be executed repeatedly across machines.

Content

Scanner excerpt · SKILL.md (reported line 209)May include surrounding context.

md
changes between machines. The 5-minute daemon interval is sufficient.
- **First-time iCloud download**: Mac B must wait for iCloud to fully download
  the `WorkBuddy-sync.git` folder before cloning. Check with `ls`.
- **LaunchAgent** (`launchctl load`) often fails with "Input/output error" on
  macOS 12+ under sandbox. The Python subprocess daemon approach is more reliable.
- **Automations** (scheduled tasks) are stored in `workbuddy.db` and do NOT sync.
  Recreate them on each machine using the `automation_update` tool.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 212)May include surrounding context.

md
- **LaunchAgent** (`launchctl load`) often fails with "Input/output error" on
  macOS 12+ under sandbox. The Python subprocess daemon approach is more reliable.
- **Automations** (scheduled tasks) are stored in `workbuddy.db` and do NOT sync.
  Recreate them on each machine using the `automation_update` tool.
- **Project workspace memory** (`<project>/.workbuddy/memory/`) is NOT inside
  `~/.workbuddy/` and must be synced separately.
- **Daemon recovery**: After reboot, the daemon restarts when the user opens

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script silently modifies the user's global git identity and default branch settings, affecting all repositories on the system, not just WorkBuddy. Hidden global configuration changes can interfere with existing development workflows, misattribute commits, and create hard-to-diagnose side effects beyond the skill's intended scope.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/setup-mac-b-icloud.sh (reported line 8)May include surrounding context.

sh
# No tokens, no SSH keys — just needs the same iCloud account.
#
# Usage (on Mac B):
#   1. Install WorkBuddy, launch once, then quit (to create ~/.workbuddy/)
#   2. Ensure iCloud Drive is enabled and WorkBuddy-sync.git has downloaded
#   3. Run: bash setup-mac-b-icloud.sh
#

Session Persistence

Medium
Category
Rogue Agent
Confidence
93% confidence
Finding

At this point the script prepares to append an auto-sync hook into the user's shell profile, establishing session persistence. Because the hook launches scripts from ~/.workbuddy on terminal open, and that directory is synchronized via iCloud-backed Git, compromise or unintended changes to synced content can become recurring code execution.

Content

Scanner excerpt · scripts/setup-mac-b-icloud.sh (reported line 90)May include surrounding context.

sh
PROFILE="$HOME/.zshrc"
fi

# Write aliases + auto-sync hook (skip if already present)
if grep -q "wbsync" "$PROFILE" 2>/dev/null; then
  echo ">> Aliases already present, skipping"
else

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script appends aliases and auto-sync logic to the user's shell profile so code in ~/.workbuddy runs on every terminal start. Because ~/.workbuddy is later populated from an iCloud-synced Git repository, this creates persistent execution of repository-controlled shell scripts without an explicit consent step at each login/session, increasing the blast radius if the synced repo is tampered with.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The shell profile is modified to auto-run sync and daemon startup logic without an explicit warning or confirmation, creating stealthy persistence. In this skill's context, the executed scripts come from a synced config repository, so future remote content changes can influence what runs whenever a terminal opens.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/start-sync-daemon.sh (reported line 38)May include surrounding context.

sh
if [ -z "$PYTHON" ]; then
  # No Python available, use pure bash background mode
  nohup /bin/bash -c "
    while true; do
      /bin/bash '$WB_DIR/auto-sync.sh' 2>/dev/null
      sleep 300

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill's purpose is syncing WorkBuddy config through iCloud, but the script writes to the user's global git configuration, setting user.name, user.email, and init.defaultBranch for all repositories on the machine. That is a system-wide capability unrelated to iCloud sync setup for a single WorkBuddy directory.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.