Back to skill

Security audit

workbuddy-multi-device-sync

Security checks for vulnerabilities and agentic risk

Overview

This skill has a coherent sync purpose, but it uses risky automatic execution, persistent background syncing, plaintext GitHub tokens, and broad agent-state synchronization.

Install only if you are comfortable with a private GitHub repo becoming the control point for WorkBuddy identity, memory, skills, and settings. Use a fine-grained short-lived token, avoid plaintext credential storage and `curl | bash`, inspect setup scripts before running them, and do not enable the daemon until you understand how to stop it and review what it syncs.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (6)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:178
Finding

Unverified Remote Script Execution Through curl-to-shell Pipeline

Content
View full analysis
`, ``, `` with actual values 2. Upload the script to the GitHub repo (commit + push from Mac A) 3. On Mac B, run one command: curl -sSL -H "Authorization: token " \ "https://raw.githubusercontent.com//wb-sync/main/wb-setup-mac-b.sh" | bash ``` ### Technical Analysis The documented command downloads a shell script from the mutable `main` branch and immediately executes it with `bash`. It does not pin an immutable commit, verify a cryptographic hash or signature, save the script for inspection, or confirm its contents with the user. Although the documented host is GitHub, the effective payload remains controlled by whoever has write access to the synchronization repository. The payload can change after this Skill has been reviewed. The GitHub token is also passed as a command-line argument to `curl`, which can expose it to local process inspection while the command is running. ### Attack Path 1. An attacker compromises the GitHub account, repository, or a token with repository write permission. 2. The attacker replaces `wb-setup-mac-b.sh` on the `main` branch with malicious shell commands. 3. A user follows the documented one-line installation command on another Mac. 4. `curl` retrieves the attacker-controlled version. 5. The pipeline passes the response directly to `bash`. 6. The malicious commands execute with all permissions available to the current macOS user. 7. The payload can modify user files, steal accessible credentials, alter WorkBuddy configuration, or install additional persistence. ### Impact Assessment Successful exploitation provides arbitrary command execution in the context of the user running the setup command. This normally does not grant root privileges automatical ...[truncated 260 chars]
Remediation
View remediation
/wb-sync//wb-setup-mac-b.sh" ``` 3. Pin the URL to an immutable reviewed commit rather than `main`. 4. Publish a trusted SHA-256 digest or cryptographic signature through a separate trusted channel and verify it before execution. 5. Prompt the user to inspect and explicitly approve the downloaded script. 6. Avoid placing access tokens directly in command-line arguments. Use a secure credential helper or a temporary configuration with appropriately restricted permissions. 7. Use a fine-grained, short-lived token limited to the single synchronization repository. ]]>

T06 · System Persistence

Error
Location
scripts/setup-mac-b.sh.template:80
Finding

Persistent Shell Startup Hook Launches a Detached Synchronization Daemon

Content
View full analysis
/dev/null; then echo ">> Aliases already present, skipping" else cat >> "$PROFILE" << 'PROFILE_EOF' # WorkBuddy multi-device sync shortcuts alias wbsync='cd ~/.workbuddy && git add -A && git commit -m "sync $(date +%m%d-%H%M)" && git push origin main' alias wbpull='cd ~/.workbuddy && git pull origin main' # WorkBuddy auto-sync — daemon keepalive + sync on terminal open if [ -f ~/.workbuddy/start-sync-daemon.sh ]; then bash ~/.workbuddy/start-sync-daemon.sh 2>/dev/null fi if [ -t 1 ] && [ -f ~/.workbuddy/auto-sync.sh ]; then _wb_now=$(date +%s) _wb_last=$(cat ~/.workbuddy/.last-auto-sync 2>/dev/null || echo 0) if [ $((_wb_now - _wb_last)) -gt 300 ]; then bash ~/.workbuddy/auto-sync.sh >/dev/null 2>&1 & echo $_wb_now > ~/.workbuddy/.last-auto-sync fi unset _wb_now _wb_last fi PROFILE_EOF echo ">> Added to $PROFILE" fi echo "" echo ">> Starting background sync daemon..." chmod +x "$WB_DIR/start-sync-daemon.sh" 2>/dev/null bash "$WB_DIR/start-sync-daemon.sh" 2>/dev/null ``` From `scripts/start-sync-daemon.sh`: ```bash if [ -z "$PYTHON" ]; then # No Python available, use pure bash background mode nohup /bin/bash -c " while true; do /bin/bash '$WB_DIR/auto-sync.sh' 2>/dev/null sleep 300 done " >/dev/null 2>&1 & echo $! > "$PID_FILE" exit 0 fi # Use Python start_new_session=True for a true daemon "$PYTHON" -c " import subprocess, os wb = os.path.expanduser('~/.workbuddy') proc = subprocess.Popen( ...[truncated 2362 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/setup-mac-b.sh.template:18
Finding

GitHub Token Is Embedded in a Script and Stored in Plaintext

Content
View full analysis
" GITHUB_TOKEN="" GITHUB_REPO="" ``` ```bash # Store GitHub credentials (HTTPS passwordless) echo "https://${GITHUB_USERNAME}:${GITHUB_TOKEN}@github.com" > "$HOME/.git-credentials" chmod 600 "$HOME/.git-credentials" git config --global credential.helper store echo ">> GitHub credentials stored" ``` The corresponding workflow in `SKILL.md` states: ```text 1. Replace ``, ``, `` with actual values 2. Upload the script to the GitHub repo (commit + push from Mac A) ``` The recommended device-flow request also uses broad scopes: ```bash curl -s -X POST "https://github.com/login/device/code" \ -H "Accept: application/json" \ -d "client_id=178c6fc778ccc68e1d6a&scope=repo,admin:public_key" ``` ### Technical Analysis The workflow directs the user to substitute a real token into the setup script and then commit and push that script. Consequently, the token can remain in the repository's current contents and immutable Git history. The script additionally writes the token into `~/.git-credentials`, using Git's plaintext `store` helper. File mode `0600` limits access to the local user but does not encrypt the credential. The requested `repo,admin:public_key` scope is broader than necessary for synchronizing one private repository. In particular, SSH public-key administration is unrelated to the documented HTTPS synchronization workflow. ### Attack Path 1. A user replaces the template placeholder with a real GitHub token. 2. The generated setup script is committed and pushed as instructed. 3. The credential remains available in the file or repository ...[truncated 922 chars]
Remediation
View remediation

T01 · Skill Instruction Hijacking

Error
Location
scripts/auto-sync.sh:25
Finding

Automatic Pull of Agent Identity, Memory, Skills, and Configuration Enables Persistent Behavior Poisoning

Content
View full analysis
/dev/null 2>&1 # 2. Commit local changes (skip if nothing staged) git add -A if ! git diff --cached --quiet 2>/dev/null; then git commit -m "auto-sync ${TS}" >/dev/null 2>&1 fi # 3. Push git push origin main >/dev/null 2>&1 ``` ### Technical Analysis The repository contains files that define Agent identity and durable behavioral state, including `SOUL.md`, `IDENTITY.md`, `USER.md`, and `MEMORY.md`. It also synchronizes installed Skills and MCP/settings configuration. Every five minutes, the daemon pulls remote changes directly into the live WorkBuddy directory without signature verification, protected-branch enforcement, semantic validation, or user approval. This creates two related security boundaries: - Changes to identity and Skill instructions can alter how the Agent interprets goals or safety constraints. - Changes to `MEMORY.md` can insert attacker-controlled durable statements that continue influencing later sessions. Synchronizing `skills/` and `mcp.json` also increases the effect of repository compromise because attacker-controlled Skill content or integration configuration can be propagated to every conn ...[truncated 1222 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/auto-sync.sh:25
Finding

Broad Automatic Git Staging Can Upload Unintended Sensitive Files

Content
View full analysis
/dev/null 2>&1 # 2. Commit local changes (skip if nothing staged) git add -A if ! git diff --cached --quiet 2>/dev/null; then git commit -m "auto-sync ${TS}" >/dev/null 2>&1 fi # 3. Push git push origin main >/dev/null 2>&1 ``` ### Technical Analysis `git add -A` stages every non-ignored change beneath `~/.workbuddy`, including new files, modifications, and deletions. The design relies entirely on the `.gitignore` template to prevent sensitive data from being uploaded. A denylist cannot reliably account for future WorkBuddy file types, renamed credential stores, temporary exports, user-created secrets, or files that were already tracked before an ignore rule was added. Moreover, the intended synchronized data already includes personal identity, memory, settings, Skills, and MCP configuration. The command executes silently every five minutes and pushes without presenting a diff or asking the user to approve newly discovered files. ### Attack Path 1. WorkBuddy, a plugin, a Skill, or the user creates a sensitive file under `~/.workbuddy`. 2. The filename is not covered by the current `.gitignore`, or the file was previously tracked. 3. The daemon executes `git add -A`. 4. The file is committed automatically. 5. `git push origin main` uploads it to GitHub. 6. Anyone with repository access, or anyone who later compromises an authorized account or token, can retrieve the data from the repository or its history. ### Impact Assessment Potentially exposed data includes personal identity and memory, service endpoints, settings, access tokens, generated scripts, and future WorkBuddy state not anticipated by the current ignor ...[truncated 137 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/setup-mac-b.sh.template:60
Finding

Forced Git Reset Can Destructively Replace Local WorkBuddy State

Content
View full analysis
> Git repo exists, switching remote to GitHub..." git remote remove origin 2>/dev/null || true git remote remove icloud 2>/dev/null || true git remote add origin "$GITHUB_REPO" git fetch origin git reset --hard origin/main else echo ">> Initializing git and pulling from GitHub..." git init git remote add origin "$GITHUB_REPO" git fetch origin git checkout -f -B main origin/main fi ``` The preceding backup is limited to selected paths: ```bash if [ -f "$WB_DIR/SOUL.md" ] || [ -f "$WB_DIR/MEMORY.md" ]; then BACKUP_DIR="$WB_DIR.backup.$(date +%Y%m%d%H%M%S)" echo ">> Backing up existing config to $BACKUP_DIR ..." mkdir -p "$BACKUP_DIR" for f in SOUL.md IDENTITY.md USER.md MEMORY.md mcp.json settings.json skills; do if [ -e "$WB_DIR/$f" ]; then cp -r "$WB_DIR/$f" "$BACKUP_DIR/" fi done echo ">> Backup complete" fi ``` ### Technical Analysis When a Git repository already exists, the script replaces its remotes and executes `git reset --hard origin/main`. Otherwise, it uses a forced checkout. These commands discard local tracked changes and replace the active configuration with remote content without displaying a diff or requesting confirmation. The backup only runs when `SOUL.md` or `MEMORY.md` exists and only copies a fixed list of paths. Other local files and repository state are not comprehensively backed up. The forced operation is particularly dangerous if `GITHUB_REPO` is incorrect or compromised. ### Attack Path 1. A user runs the setup script on a WorkBuddy directory containing local changes or an existing repository. 2. The configured repository points to unintended, stale, or attacker-con ...[truncated 775 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (37)

Credential Access

High
Category
Privilege Escalation
Confidence
98% confidence
Finding

The skill instructs storing a GitHub access token in ~/.git-credentials as a plaintext URL containing the username and token. Plaintext long-lived credentials are vulnerable to theft by local malware, backups, accidental disclosure, or later inclusion in sync/diagnostic outputs, enabling repository compromise and unauthorized code changes across machines.

Content

Scanner excerpt · SKILL.md (reported line 95)May include surrounding context.

  1. Store credentials:
bash
echo "https://<USERNAME>:<TOKEN>@github.com" > ~/.git-credentials
chmod 600 ~/.git-credentials
git config --global credential.helper store

Credential Access

High
Category
Privilege Escalation
Confidence
97% confidence
Finding

Configuring git credential.helper store persists credentials unencrypted on disk, extending the lifetime and discoverability of the GitHub token. If the machine or account is compromised, the token can be reused to access and modify the sync repository and any connected setup scripts.

Content

Scanner excerpt · SKILL.md (reported line 96)May include surrounding context.

  1. Store credentials:
bash
echo "https://<USERNAME>:<TOKEN>@github.com" > ~/.git-credentials
chmod 600 ~/.git-credentials
git config --global credential.helper store

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

Directing users to create a Personal Access Token with broad repo scope increases exposure if that token is mishandled, especially when combined with plaintext storage and remote script execution from the same repo. The issue is not token creation itself, but the broad and persistent credential model the skill promotes.

Content

Scanner excerpt · SKILL.md (reported line 111)May include surrounding context.

md
**Approach B: Manual setup**

1. User creates a private repo at https://github.com/new (name: `wb-sync`, private, no README)
2. User creates a Personal Access Token at https://github.com/settings/tokens/new (scope: `repo`)
3. Store credentials as shown above

#### Step 4: Push to GitHub

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly directs the user to escape the sandbox using osascript or dangerouslyDisableSandbox to start a daemon. Bypassing execution controls increases the blast radius of any mistake or malicious modification in the referenced script and defeats expected runtime safety boundaries.

Content

No source excerpt is available for this finding.

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

Piping downloaded content directly into bash chains network retrieval to code execution with no validation boundary. In this skill, that risk is amplified because the same workflow also provisions repository write access, so an attacker who alters the repo can turn future setup runs into arbitrary code execution across devices.

Content

Scanner excerpt · SKILL.md (reported line 184)May include surrounding context.

bash
curl -sSL -H "Authorization: token <TOKEN>" \
  "https://raw.githubusercontent.com/<USERNAME>/wb-sync/main/wb-setup-mac-b.sh" | bash

The script automatically:

Credential Access

High
Category
Privilege Escalation
Confidence
93% confidence
Finding

The note normalizes token storage in ~/.git-credentials and only suggests limited scope/expiration as a secondary consideration, which understates the risk of plaintext secret persistence. This reinforces an unsafe pattern for handling credentials in a workflow that also executes code sourced from the same repository.

Content

Scanner excerpt · SKILL.md (reported line 225)May include surrounding context.

md
- **Project workspace memory** (`<project>/.workbuddy/memory/`) is NOT inside
  `~/.workbuddy/` and must be synced separately (via the project's own Git repo
  or cloud storage).
- **Token security**: The GitHub token is stored in `~/.git-credentials` (chmod 600).
  For shared machines, consider using a token with limited scope and expiration.
- **Daemon recovery**: After a machine reboot, the daemon restarts automatically
  when the user opens a terminal (via the `.bash_profile` hook) or when WorkBuddy

Credential Access

High
Category
Privilege Escalation
Confidence
99% confidence
Finding

Referencing ~/.git-credentials here is not merely incidental; the surrounding command writes a reusable GitHub token to a plaintext credential store. That creates a credential access risk for any local malware, other local users, backup systems, or accidental file disclosure, and in this skill's context it could grant write access to the sync repository containing trusted agent state and skills.

Content

Scanner excerpt · references/sync-architecture.md (reported line 71)May include surrounding context.

Symptom: git push returns 403 Forbidden Fix: Generate new token at https://github.com/settings/tokens/new

bash
echo "https://<user>:<new_token>@github.com" > ~/.git-credentials

Merge conflicts during auto-sync

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The daemon silently performs git pull, git add -A, git commit, and git push every five minutes, modifying files and sending data to a remote without any runtime notice or confirmation. Because it stages all changes under ~/.workbuddy, this can automatically exfiltrate sensitive memories, settings, tokens, or newly added files and can also overwrite local state after remote changes, making the skill context especially risky.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script writes a GitHub personal access token directly into ~/.git-credentials in plaintext and enables git credential.helper store, causing long-lived credential persistence on disk. Any local process, backup system, or later user compromise of the account can recover the token and use it to access or modify the associated GitHub resources.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
99% confidence
Finding

Referencing and creating ~/.git-credentials here is part of a credential persistence mechanism that stores a GitHub token in plaintext. In the context of a sync/setup skill, this is more dangerous because it normalizes unattended background access and increases the window in which stolen local files can yield reusable GitHub credentials.

Content

Scanner excerpt · scripts/setup-mac-b.sh.template (reported line 53)May include surrounding context.

text
fi

# Store GitHub credentials (HTTPS passwordless)
echo "https://${GITHUB_USERNAME}:${GITHUB_TOKEN}@github.com" > "$HOME/.git-credentials"
chmod 600 "$HOME/.git-credentials"
git config --global credential.helper store
echo ">> GitHub credentials stored"

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

This line changes permissions on ~/.git-credentials, confirming the presence of a sensitive credential file that contains persisted GitHub authentication material. The issue is not the chmod itself but the existence of the plaintext credential store, which can be harvested by anyone who gains access to the user account or backups.

Content

Scanner excerpt · scripts/setup-mac-b.sh.template (reported line 54)May include surrounding context.

text
# Store GitHub credentials (HTTPS passwordless)
echo "https://${GITHUB_USERNAME}:${GITHUB_TOKEN}@github.com" > "$HOME/.git-credentials"
chmod 600 "$HOME/.git-credentials"
git config --global credential.helper store
echo ">> GitHub credentials stored"

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script performs git fetch followed by git reset --hard origin/main or force-checkout of origin/main, which overwrites local ~/.workbuddy state without requiring explicit approval at the destructive step. Although a partial backup is attempted earlier, it is incomplete and does not eliminate the risk of silent data loss or replacement of trusted local configuration with remote content.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

git reset --hard origin/main is a destructive command that forcibly discards local tracked changes and replaces them with remote state. In this skill context, the risk is elevated because the remote repository becomes a control point for WorkBuddy configuration and synced scripts, so users can lose local data and unknowingly trust remote content without review.

Content

Scanner excerpt · scripts/setup-mac-b.sh.template (reported line 67)May include surrounding context.

text
git remote remove icloud 2>/dev/null || true
  git remote add origin "$GITHUB_REPO"
  git fetch origin
  git reset --hard origin/main
else
  echo ">> Initializing git and pulling from GitHub..."
  git init

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill instructs users to perform file writes, shell execution, daemon setup, and shell profile modification, but it declares no explicit tool scope or permissions. This creates a capability/expectation mismatch that reduces reviewability and increases the chance that powerful actions are executed without appropriate policy gating.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 55)May include surrounding context.

git init

text

#### Step 2: Create `.gitignore`

Copy the template from `references/gitignore-template` to `~/.workbuddy/.gitignore`.
This excludes all machine-specific files. Review and adjust as needed.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 77)May include surrounding context.

  1. Initiate device flow to get a verification code:
bash
curl -s -X POST "https://github.com/login/device/code" \
  -H "Accept: application/json" \
  -d "client_id=178c6fc778ccc68e1d6a&scope=repo,admin:public_key"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 96)May include surrounding context.

  1. Store credentials:
bash
echo "https://<USERNAME>:<TOKEN>@github.com" > ~/.git-credentials
chmod 600 ~/.git-credentials
git config --global credential.helper store

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 104)May include surrounding context.

bash
curl -s -X POST -H "Authorization: token <TOKEN>" \
  -H "Accept: application/vnd.github+json" \
  "https://api.github.com/user/repos" \
  -d '{"name":"wb-sync","private":true,"description":"WorkBuddy config sync"}'

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 171)May include surrounding context.

md
### Phase 2: Set Up Mac B (Additional Machines)

#### Prerequisites
- WorkBuddy installed and launched once (to create `~/.workbuddy/` directory), then quit
- Terminal access
- GitHub reachable (directly or via proxy)

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The one-liner fetches a remote script and immediately executes it with bash, giving the fetched content arbitrary code execution on the target Mac. Because the script is pulled from a mutable remote location and authorized with a token, compromise of the repo, token, or network path could lead to full user-level execution beyond the stated sync purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill recommends remote script execution without prominently warning that the command grants arbitrary code execution and should only be used after integrity verification. Users may treat it as a routine setup step and execute unreviewed code with access to local configuration and credentials.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

The skill advocates a recurring background daemon and explains how it survives through terminal-start hooks after reboot, which is a form of persistence. While aligned with the sync goal, persistence increases risk because any compromise of the synced scripts or repository can gain repeated execution on every affected machine.

Content

Scanner excerpt · SKILL.md (reported line 217)May include surrounding context.

md
## Important Notes

- **GitHub SSH port 22 may be blocked** in China. Use HTTPS + token instead.
- **LaunchAgent** (`launchctl load`) often fails with "Input/output error" on macOS 12+
  under sandbox. The Python subprocess daemon approach in `start-sync-daemon.sh`
  is more reliable.
- **Automations** (scheduled tasks) are stored in `workbuddy.db` and do NOT sync.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 221)May include surrounding context.

md
under sandbox. The Python subprocess daemon approach in `start-sync-daemon.sh`
  is more reliable.
- **Automations** (scheduled tasks) are stored in `workbuddy.db` and do NOT sync.
  Recreate them on each machine using the `automation_update` tool.
- **Project workspace memory** (`<project>/.workbuddy/memory/`) is NOT inside
  `~/.workbuddy/` and must be synced separately (via the project's own Git repo
  or cloud storage).

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/sync-architecture.md (reported line 38)May include surrounding context.

Daemon Architecture

The sync daemon uses Python's subprocess.Popen with start_new_session=True to create a truly detached process that survives terminal close.

text
.bash_profile → start-sync-daemon.sh → Python subprocess → bash loop

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/sync-architecture.md (reported line 49)May include surrounding context.

text

### Why not LaunchAgent?
On macOS 12+, `launchctl load` frequently fails with "Input/output error" under
sandbox restrictions. The Python daemon approach is more reliable and doesn't
require elevated permissions.

Static analysis

No suspicious patterns detected.