Back to skill

Security audit

Xcode Cache Cleaner

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches an Xcode cache-cleaning purpose, but one cleanup script can execute unintended shell commands if given a crafted directory path.

Review before installing. Do not run artifact/scripts/clean-cache.sh on untrusted or externally supplied directory names until the eval-based find construction is fixed. Use dry-run first, inspect exact paths, avoid --yes unless you already approved the scope, and be especially careful with --include-archives because it can delete signed archive builds.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/clean-cache.sh:54
Finding

Arbitrary Command Execution Through Target Directory Path Injection

Content
View full analysis
/dev/null" || true) ``` ### Technical Analysis The script accepts a user-controlled target directory and resolves it to an absolute path. Although the path is quoted when initially passed to `cd`, resolving it with `pwd` does not remove shell metacharacters from directory names. The resolved path is subsequently interpolated into a command string passed to `eval`. `eval` causes the shell to parse the generated string again. A valid directory name containing a double quote and additional shell syntax can therefore terminate the intended quoted argument and introduce arbitrary commands. For example, a directory path conceptually containing syntax such as: ```text /tmp/cache"; attacker_command; # ``` can transform the generated command into the equivalent of: ```bash find "/tmp/cache"; attacker_command; #" -name .build -type d ... -print0 ``` The injected command is then executed by the shell. The vulnerability is reachable during the scanning phase, so using `--dry-run` does not prevent exploitation. It is also reached before the cleanup confirmation prompt. The hard-coded `find_args` values are not themselves attacker-controlled, but that does not protect the separately interpolated `TARGET_DIR`. ### Attack Path 1. An attacker creates or controls a directory whose name contains shell metacharacters that break out of the double-quoted `find` argument. 2. The attacker persuades a user or agent to scan that directory, or supplies it as the requested project directory. 3. The script successfully ...[truncated 1216 chars]
Remediation
View remediation
/dev/null || true) ``` Because each cache pattern uses different predicates, define each expression as an array or implement a dedicated function for each supported cache type. Do not store executable shell fragments in strings. Additional hardening should include: 1. Validate that the resolved target is an existing directory. 2. Keep `--` separators where supported when passing potentially attacker-controlled paths to utilities. 3. Avoid command-string construction for all filesystem operations. 4. Add automated regression tests using target paths containing spaces, quotes, semicolons, dollar signs, command-substitution syntax, glob characters, leading hyphens, and newlines. 5. Verify in tests that neither normal scans nor `--dry-run` execute pathname contents as commands. 6. Consider refusing especially dangerous cleanup targets such as `/`, the user’s home directory, or other broad system locations unless explicitly supported and separately confirmed. ]]>
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The code generally matches the broad idea of cleaning build artifacts, especially per-project caches, but it materially underdelivers on the description’s primary Xcode-specific promises. The description emphasizes first-class support for global Xcode cache locations and simulator/device support cleanup on a Mac dev machine. This script does not access those locations at all; it only scans within a user-supplied target directory. While it does support deleting project-local items like SPM .build, Pods, Carthage, xcresult, and some generic caches, the absence of the headline Xcode/global cleanup capabilities makes the description inaccurate overall.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
89% confidence
Finding

The skill supports a non-interactive --yes flag and explicitly suggests using it when an agent is driving, enabling autonomous deletion of caches and potentially archives without a fresh human confirmation at execution time. In this context, the danger is increased because the skill targets broad filesystem locations under ~/Library/Developer and can remove large amounts of developer state, including optional signed archives, making accidental destructive actions more likely.

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

md
Flags:
- `--dry-run` — Scan and report only, no deletions
- `--yes` / `-y` — Skip confirmation prompt (use when agent is driving)
- `--keep-ios <pattern>` — Keep DeviceSupport folders matching this substring (repeatable). Applied across all `*OS DeviceSupport` dirs, not just iOS.
- `--include-archives` — Also delete `Archives/*` (default: keep)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This shell script includes multiple user-facing strings in Chinese, such as subtotal, Git info, summary, confirmation, and completion messages, without offering any language choice. The policy requires avoiding forced language or locale constraints unless the user opts in or the regional restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · scripts/clean-xcode-global.sh (reported line 21)May include surrounding context.

sh
#
# --include-archives    Also delete Archives/* (off by default — these are your signed .ipa archives!)
# --dry-run             Scan and report only, no deletions
# --yes / -y            Skip confirmation prompt

set -euo pipefail

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This shell script emits mandatory user-facing status text in Chinese, such as the main banner at L071, without offering a language choice or documenting that the skill is intentionally Chinese-only. That is a natural-language locale policy issue under the rule because the script imposes a specific language on all users.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.