Back to skill

Security audit

iOS Simulator Skill

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent iOS Simulator automation skill with expected simulator data access and state-changing commands that should be used deliberately on test devices.

Install this only on macOS/Xcode environments intended for iOS testing. Treat simulator clipboard contents, UI dumps, logs, app containers, and push payloads as potentially sensitive, be careful with erase/delete and --all, and consider pinning or verifying idb-related dependencies in stricter environments.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:66
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:66-70; duplicated in references/TROUBLESHOOTING.md:19-24
Vulnerability Type: Unpinned and mutable third-party dependencies
Risk Level: Medium

Vulnerable Code

SKILL.md:66-70:

bash
brew tap facebook/fb
brew install idb-companion
python3 -m pip install --upgrade fb-idb

references/TROUBLESHOOTING.md:19-24:

bash
Install:
```bash
brew tap facebook/fb
brew install idb-companion
python3 -m pip install --upgrade fb-idb
text

### Technical Analysis

The installation instructions retrieve the latest available versions of `idb-companion` and `fb-idb` from mutable Homebrew and PyPI sources. No reviewed version, lockfile, package hash, immutable artifact, or integrity verification is specified. The explicit `--upgrade` option further ensures that a future invocation may install code that did not exist when this Skill was audited.

This does not demonstrate that the named dependencies are currently malicious. However, it creates supply-chain exposure: compromise of an upstream maintainer account, package registry, Homebrew tap, release artifact, or transitive dependency could cause users following these instructions to install attacker-controlled code.

### Attack Path

1. An attacker compromises an upstream package publisher, release process, Homebrew tap, registry account, or relevant transitive dependency.
2. The attacker publishes a malicious release under the expected dependency name.
3. A user follows the Skill documentation and runs the unpinned installation commands.
4. Homebrew or `pip --upgrade` resolves the mutable malicious release instead of a previously reviewed version.
5. Malicious installation or package code executes in the installing user's environment.
6. The package may subsequently execute again whenever the Skill invokes `idb`.

### Impact Assessment

Successful exploitation can execute code with the pri
...[truncated 409 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin idb-companion and fb-idb to explicitly reviewed versions rather than installing the latest releases.
  2. Remove unconditional --upgrade behavior from the standard installation path.
  3. For Python dependencies, publish a requirements or constraints file containing exact versions and cryptographic hashes, then install with pip --require-hashes.
  4. Pin or otherwise verify the Homebrew formula or artifact revision where operationally feasible.
  5. Document the expected package publisher, repository, and release checksums so users can verify provenance.
  6. Review and update pinned versions through a controlled dependency-update process with changelog, integrity, and security checks.
  7. Prefer isolated environments for Python tools to limit package conflicts and exposure.

T09 · Insecure Skill Coding Practices

Note
Location
scripts/ios-sim.mjs:692
Finding

Push Notification Payload Stored in Predictable and Persistent Temporary File

Content
View full analysis

Vulnerability Details

File Location: scripts/ios-sim.mjs:692-698
Vulnerability Type: Unsafe temporary-file handling and residual plaintext data
Risk Level: Low

Vulnerable Code

js
const tmpPath = path.join(os.tmpdir(), `sim-push-${nowIsoCompact()}.apns.json`);
fs.writeFileSync(tmpPath, JSON.stringify(payloadObj), "utf8");

await run("xcrun", ["simctl", "push", resolvedUdid, bundleId, tmpPath], { allowNonZero: true });

emit({ ok: true, udid: resolvedUdid, bundleId, tmp: tmpPath, summary: ["Push sent"] }, { pretty, text });

Technical Analysis

The temporary APNs payload filename is derived only from the current timestamp. It is not generated using a cryptographically random value or an atomically created private temporary directory. The file is written without exclusive-creation flags and without an explicit restrictive mode such as 0600.

fs.writeFileSync follows existing symbolic links and ordinarily creates files according to the process umask. On common configurations this can result in a file readable by other local users. The code also never deletes the file after simctl push completes, leaving notification contents in the operating system's temporary directory indefinitely until an external cleanup process removes them.

Push payloads can contain private test messages, account identifiers, internal URLs, tokens, or other application data. The predictable path and retained plaintext therefore create local confidentiality exposure. A same-user malicious process may also monitor or pre-create candidate paths, potentially redirecting or modifying the file before simctl consumes it.

Attack Path

A confidentiality attack can proceed as follows:

  1. A user invokes the push command with a payload containing sensitive test data.
  2. The Skill serializes the payload into a timestamp-named file under os.tmpdir().
  3. The file receives permissions derived from the process umask and ...[truncated 1354 chars]
Remediation
View remediation

Remediation Suggestions

  1. Create a private temporary directory with fs.mkdtempSync, using a prefix under os.tmpdir().
  2. Create the payload file with exclusive creation and mode 0600, for example by using flags equivalent to wx and an explicit file mode.
  3. Place the simctl push invocation inside a try block and delete the payload file and temporary directory in a finally block.
  4. Do not return the temporary pathname in normal output unless required for diagnostics.
  5. Minimize sensitive information in test notification payloads and avoid embedding reusable credentials or production tokens.
  6. Handle cleanup failures explicitly without exposing payload contents in error messages.

A hardened pattern should resemble:

js
const tmpDir = fs.mkdtempSync(path.join(os.tmpdir(), "sim-push-"));
const tmpPath = path.join(tmpDir, "payload.apns.json");

try {
  fs.writeFileSync(tmpPath, JSON.stringify(payloadObj), {
    encoding: "utf8",
    flag: "wx",
    mode: 0o600,
  });
  await run("xcrun", [
    "simctl", "push", resolvedUdid, bundleId, tmpPath,
  ]);
} finally {
  fs.rmSync(tmpDir, { recursive: true, force: true });
}
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/TROUBLESHOOTING.md (reported line 7)May include surrounding context.

md
- Ensure Xcode / Command Line Tools are installed.
- Ensure the correct developer dir is selected:
  - `xcode-select -p` to view
  - `sudo xcode-select -s /Applications/Xcode.app` (or your Xcode path)
- Run first-launch component install:
  - `xcodebuild -runFirstLaunch`

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The clipboard get command reads and emits clipboard contents directly, which may include passwords, tokens, or other sensitive user data. While the action is visible in code, there is no confirmation prompt or explicit user-facing warning in the command help/comments describing the privacy impact of reading clipboard data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The ui tree command emits all UI accessibility elements from the simulator, which can include labels, values, and other content visible in the app UI. The file does not provide a user warning that this output may contain sensitive personal or application data before returning the full tree.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The ui type command sends arbitrary text to the currently focused UI element in the simulator, which can alter app state or submit sensitive content unintentionally. The command executes without any confirmation or user-facing warning about typing into whichever field is active.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/ios-sim.mjs:142