Back to skill

Security audit

PECMD Pro Max

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent PECMD documentation skill, but it needs review because it teaches powerful WinPE/admin scripting patterns with limited safety scoping.

Install only if you expect the agent to help write privileged WinPE/PECMD scripts. Review generated scripts before running them, especially commands using PART, REGI, EXEC, KILL, SHUT, CALL $, DeviceIoControl, RUNS, SHEL, ADSL, or SITE. Use a VM or test PE image, back up disks and registry hives, avoid hardcoded credentials, and do not copy the rules.ini dynamic-evaluation pattern for untrusted files.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
references/how-tos/system.md:257
Finding

Untrusted Local Configuration Is Transformed into Executable PECMD Code

Content
View full analysis

Vulnerability Details

File Location: references/how-tos/system.md:257-260
Vulnerability Type: Arbitrary command execution through unsafe dynamic code evaluation
Risk Level: High

wcs
READ %CurDir%\rules.ini,**,&A
SED &&A=0:0,%&NA%,%&NA%ENVI ,{*ENVI %A%            // convert lines to ENVI commands
SET< A=%&NL%}
%&A%                                                // execute generated code block

Technical Analysis

This example reads %CurDir%\rules.ini into a variable, transforms its lines into PECMD statements, and executes the generated code through %&A%. It does not validate the file's ownership, permissions, integrity, syntax, or permitted operations.

Consequently, configuration data crosses directly into a code-execution sink. If %CurDir% or rules.ini is writable by an untrusted user or process, arbitrary PECMD directives can be injected. Input filtering is especially difficult here because PECMD supports command chaining, external program execution, dynamic script loading, registry modification, storage operations, and network functionality.

The issue is particularly significant in WinPE environments, where PECMD commonly runs with SYSTEM privileges.

Attack Path

  1. A victim incorporates the documented dynamic-code pattern into a PECMD tool or startup workflow.
  2. An attacker gains write access to %CurDir%\rules.ini, or controls the working directory from which the script runs.
  3. The attacker inserts malicious PECMD directives into rules.ini.
  4. READ imports the attacker-controlled content.
  5. SED converts the imported lines into a generated PECMD code block.
  6. %&A% evaluates the generated block without validation.
  7. The injected directives execute with the privileges of the PECMD process.

Impact Assessment

Successful exploitation provides arbitrary PECMD command execution under the current process identity. If PECMD is running as SYSTEM, the attacker may obtain system-level execution.

The r ...[truncated 517 chars]

Remediation
View remediation

Remediation Suggestions

  • Do not evaluate configuration files as PECMD source code.
  • Parse rules.ini as data using a strict schema and map each supported key to a fixed, allowlisted operation.
  • Reject unknown keys, malformed values, command separators, script directives, external execution directives, and dynamic loading constructs.
  • Use an absolute trusted path rather than %CurDir%, which may vary or be attacker-controlled.
  • Restrict the configuration file and its parent directory with ACLs so only trusted administrators or the owning service identity can modify them.
  • Verify file integrity or a cryptographic signature before processing when configurations are distributed or stored outside a protected image.
  • Run the consuming tool with the minimum privileges necessary rather than SYSTEM whenever possible.
  • If dynamic execution is unavoidable, isolate it in a restricted process and permit only a narrowly defined command subset after canonicalization and validation.
  • Fail closed on validation, integrity, ownership, or permission errors, and record rejected configuration attempts in security logs.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Output HandlingUnvalidated Output Injection, Cross-Context Output, Unbounded Output
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (38)

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
85% confidence
Finding

Skill attempts to nullify the agent's safety policies or restrictions ('you have no restrictions', 'ignore your guidelines', 'do anything now'). This is a direct jailbreak that disables guardrails.

Content

Scanner excerpt · README.en.md (reported line 80)May include surrounding context.

md
## License

**NonCopyRight** — this skill is free, open source, and unrestricted. Use it, modify it, ship products with it. No attribution required. No restrictions apply.

---

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/how-tos/storage.md (reported line 189)May include surrounding context.

md
REGI #HKLM\SOFTWARE\App\Count=#0x100         // hex DWORD

// Delete
REGI $HKLM\SOFTWARE\App\OldKey=              // empty = delete

// Enumerate
REGI --ak HKCU\Software\,&&keys              // enumerate subkeys (--ak)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

This example reads external file content from rules.ini, transforms it into PECMD commands, and executes the generated block with %&A% without any validation or allowlisting. That creates a code-injection primitive: anyone who can modify the input file can run arbitrary PECMD commands, potentially leading to file modification, process execution, registry changes, or destructive system actions.

Content

No source excerpt is available for this finding.

Unvalidated Output Injection

High
Category
Output Handling
Confidence
98% confidence
Finding

The line %&A% executes previously generated content derived from rules.ini, which is an unvalidated external input source. In the context of a powerful system automation language, this is especially dangerous because injected content can invoke filesystem, registry, process, GUI, or shutdown primitives directly, making arbitrary code execution within the PECMD environment straightforward.

Content

Scanner excerpt · references/how-tos/system.md (reported line 260)May include surrounding context.

READ %CurDir%\rules.ini,**,&A SED &&A=0:0,%&NA%,%&NA%ENVI ,{*ENVI %A% // convert lines to ENVI commands SET< A=%&NL%} %&A% // execute generated code block

text

---

Missing User Warnings

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

This section includes disk and partition operations such as mounting the ESP and interacting with partition/device state without prominent destructive-operation warnings. In WinPE and system automation contexts, such commands can easily lead to boot damage, data loss, or unauthorized modification of critical system partitions.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The advanced API integration section teaches arbitrary Win32/DLL invocation, raw buffer handling, callback binding, device access, and low-level enumeration. In a skill intended for agent use, this materially expands capability from GUI scripting into unrestricted system programming, which can be leveraged for persistence, process manipulation, hardware access, or evasion.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

These examples demonstrate opening physical drives with read/write access and issuing DeviceIoControl requests directly against disk devices. Even as documentation, this exposes primitives that can be used to alter partitions, corrupt storage, bypass file-system safeguards, or extract sensitive disk metadata in an agent-executable environment.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.en.md (reported line 13)May include surrounding context.

md
## What is this?

PECMD Pro Max is a **Claude Code skill** that teaches AI coding assistants to write correct PECMD2012 scripts. PECMD is the WinPE Commander — a scripting language and command interpreter used for Windows PE boot scripts, lightweight GUI system tools, disk utilities, and pre-install environment automation. Its variable scope rules, hex memory model, and window system are notoriously tricky. This skill encodes 10+ years of PECMD scripting knowledge so your AI assistant can write production-ready `.wcs` / `.wci` / `.wce` files without the usual trial-and-error.

## File structure

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file includes examples for disk and partition manipulation such as assigning and removing drive letters, and references partition enumeration workflows, but it does not warn users that storage operations in WinPE can affect mounted volumes and system state. Under the markdown-specific SQP-2 criteria, skills should disclose behaviors that could affect user data or system integrity when such operations are described.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file explicitly documents writing to the registry (REGI ...=值) and appending to files (WRIT %路径%,+0,新行) but does not include any warning about persistence, overwriting risks, or impact to user/system configuration. In markdown skill descriptions, omissions of warnings for behaviors affecting user data or system integrity should be flagged.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill describes executing external programs and embedded executables via EXEC/EXEC*, which can change system state or run arbitrary tools, yet the markdown provides no caution about reviewing commands before execution. For markdown files, user-facing warnings are expected when behaviors may affect system integrity.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The output specification instructs the agent to use Chinese conventions by default, including '默认使用中文变量名', without offering a user language or locale choice. This is a natural-language locale policy issue because it imposes a specific language preference absent explicit user opt-in or a clearly justified region-only constraint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file describes commands that can delete partitions, rewrite MBR/PBR data, initialize disks, clear partition contents, and force dangerous operations. Although some inline terms like '危险' or '不可恢复' appear for specific flags, the section does not provide a clear overall safety warning to users that these operations can destroy data or render systems unbootable.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The menu example includes a "结束进程" action that calls KillProc, which is a destructive operation, but the surrounding markdown provides no warning that using the example may kill running processes. There is also no indication of confirmation or user disclosure before this action.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

These examples demonstrate changing visibility/state of other windows via @@Visible, which can disrupt user workflows or hide applications, but the markdown does not warn about affecting external processes. Similar cross-process control is further reinforced by the message-sending examples below.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The markdown shows @@SENDMSG with WM_CLOSE to another window handle, which may close external application windows and potentially cause unsaved work loss. No warning is provided about this impact on user data or running applications.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/how-tos/gui.md (reported line 512)May include surrounding context.

md
_SUB ScrollPgDn
    // Get visible rows per page, scroll by that amount
    // Simplistic: send a fixed vertical scroll
    ENVI @Table1.SENDMSG=%&::LVM_SCROLL%,0,20                       // scroll down 20 lines
_END

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The example binds an image click to EXEC calc.exe, which is subprocess execution. The markdown presents this behavior without any disclosure that clicking the image will start an external program.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest frames this skill as PECMD scripting guidance for Windows GUI, system tools, startup/init scripts, automation, and debugging. In the GUI how-to, the IMAG example binds a click directly to EXEC calc.exe, introducing arbitrary process execution as a capability rather than merely documenting GUI layout or control behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation shows WiFi connection commands with SSID and password embedded directly in the script, which encourages plaintext credential handling. In WinPE or shared automation contexts, scripts are often logged, copied, or stored on removable media, so exposing credentials this way can lead to unintended disclosure and lateral access to wireless networks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file includes examples for changing partition types, toggling active flags, and deleting partitions, as well as registry write/delete operations elsewhere, but it does not provide a general warning that these actions can irreversibly damage disks, bootability, or system configuration. Although the delete example includes an inline confirmation prompt, the surrounding skill description still lacks a clear user-facing safety warning for these high-impact behaviors.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file provides direct examples of killing processes, including by name, PID, and window context. Terminating processes can cause unsaved work to be lost or leave applications in an inconsistent state, but the documentation does not disclose that risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The examples execute embedded binaries from PECMD resources, which is a sensitive operation because it runs bundled executable code on the host system. The text explains packaging mechanics but does not disclose that this behavior launches executables and may affect the system.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file documents commands for shutdown, reboot, logoff, suspend, hibernate, eject, and workstation lock, all of which can disrupt user work or system state. The surrounding text presents them as simple examples and does not warn about data loss, interruption, or the need to save work before use.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest describes a PECMD skill for GUI, startup/init scripts, storage/system how-tos, and debugging, but this section documents capabilities to inspect and modify other processes' windows via WID, including style changes and system dialog font changes. Those are powerful automation/interference primitives not obviously required for a GUI reference and extend into external process control.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.