T06 · System Persistence
- Location
scripts/install-autopush.sh:74- Finding
Recurring Cross-Session Execution Through Windows Scheduled Tasks
- Content
View full analysis
/dev/null || echo "C:\\Program Files\\Git\\bin\\bash.exe")" SCRIPT_WIN="$(cygpath -w "$AUTOPUSH" 2>/dev/null || echo "$AUTOPUSH")" schtasks //create //tn "$TASK" //tr "\"$BASH_WIN\" \"$SCRIPT_WIN\"" //sc MINUTE //mo "$MIN" //f >/dev/null 2>&1 if [ $? -eq 0 ]; then echo "task registered: $TASK (every ${MIN}min)" else echo "task FAILED (schtasks) - run manually with admin if needed" fi echo "done." ``` ### Technical Analysis The installer registers the generated `autopush.sh` as a Windows scheduled task that runs every configured number of minutes, with a default interval of 30 minutes. The `/f` option forcibly replaces an existing task with the same name. This behavior is persistent across Agent sessions and potentially across system restarts. Although scheduled synchronization is disclosed in `README.md` and `SKILL.md`, it is broader than the minimum behavior required for “push on commit,” because the installed Git `post-commit` hooks already provide event-driven pushing. The generated script does more than retry existing commits: it inspects each configured repository, stages changes, creates commits, and pushes them. Consequently, this persistent task continuously performs repository-changing operations without renewed user approval. ### Attack Path 1. The user or Agent runs `install-autopush.sh`. 2. The installer creates an executable `autopush.sh` in the selected output directory. 3. The installer registers that script under the user-controlled task name using `schtasks`. 4. Windows launches Bash and the generated script at every configured interval. 5. The script repeatedly processes and pushes repository contents after the original Skill executi ...[truncated 739 chars]- Remediation
View remediation
