Back to skill

Security audit

TRIGGERcmd - Run commands on your computers remotely

Security checks for vulnerabilities and agentic risk

Overview

This skill enables remote TRIGGERcmd command listing and execution using the user's own token, and the sensitive behavior is disclosed and aligned with its stated purpose.

Install only if you intend the agent to list and trigger commands on computers connected to your TRIGGERcmd account. Prefer a temporary TRIGGERCMD_TOKEN when possible, keep any token file private, rotate the token if exposed, and require clear confirmation before running commands that could change files, launch programs, or affect remote systems.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 15)May include surrounding context.

md
"env": ["TRIGGERCMD_TOKEN"],
          "credentials": {
            "primary": "TRIGGERCMD_TOKEN environment variable",
            "fallback": "~/.TRIGGERcmdData/token.tkn file (chmod 600)"
          }
        }
      },

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 36)May include surrounding context.

md
"env": ["TRIGGERCMD_TOKEN"],
          "credentials": {
            "primary": "TRIGGERCMD_TOKEN environment variable",
            "fallback": "~/.TRIGGERcmdData/token.tkn file (chmod 600)"
          }
        }
      },

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 37)May include surrounding context.

md
"env": ["TRIGGERCMD_TOKEN"],
          "credentials": {
            "primary": "TRIGGERCMD_TOKEN environment variable",
            "fallback": "~/.TRIGGERcmdData/token.tkn file (chmod 600)"
          }
        }
      },

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

The skill instructs users to persist a long-lived API token in ~/.TRIGGERcmdData/token.tkn, creating a reusable local credential that can survive across sessions. If the local account or home directory is compromised, an attacker could use that token to enumerate and remotely trigger commands on associated machines.

Content

Scanner excerpt · SKILL.md (reported line 37)May include surrounding context.

md
2. **Token File**: Store token at `~/.TRIGGERcmdData/token.tkn`
   - The file should contain only the raw token text (no quotes, spaces, or trailing newline)
   - Must be permission-restricted: `chmod 600 ~/.TRIGGERcmdData/token.tkn`
   - To create: `mkdir -p ~/.TRIGGERcmdData && read -s TOKEN && printf "%s" "$TOKEN" > ~/.TRIGGERcmdData/token.tkn && chmod 600 ~/.TRIGGERcmdData/token.tkn`

**Obtaining your token:**
1. Log in at https://www.triggercmd.com

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

The skill sends authenticated POST requests to TRIGGERcmd's remote execution endpoint, which can trigger actions on enrolled computers. While this is the intended functionality, it still represents a real security-sensitive capability because compromise, misuse, or insufficient confirmation could result in unauthorized remote command execution on user devices.

Content

Scanner excerpt · SKILL.md (reported line 91)May include surrounding context.

md
--arg params "$PARAMS" \
  '{computer: $computer, command: $command, params: $params}')

curl -sS -X POST "${BASE_URL}/run/trigger" \
  "${AUTH_HEADER[@]}" \
  -H "Content-Type: application/json" \
  -d "$PAYLOAD"

Session Persistence

Medium
Category
Rogue Agent
Confidence
76% confidence
Finding

This guidance reinforces creation and continued use of a persistent token file, which increases the attack window compared with session-only credentials. In the context of a remote-command service, persistent credential storage is more sensitive because the token grants access to list and trigger commands on registered computers.

Content

Scanner excerpt · SKILL.md (reported line 105)May include surrounding context.

md
## Error Handling

- **Missing token file**: Explain how to create `~/.TRIGGERcmdData/token.tkn` and remind them to keep it private.
- **Invalid token (401/403)**: Ask the user to regenerate the token and overwrite the file.
- **Computer not found**: Show the available computer names (case-insensitive match).
- **Command not found**: List the commands for the requested computer; highlight commands with `allowParams: true` when relevant.

Static analysis

No suspicious patterns detected.