T06 · System Persistence
- Location
SKILL.md:16- Finding
Persistent User-Level Service Installed Through a macOS LaunchAgent
- Content
View full analysis
~/Library/LaunchAgents/ai.wren.recall-local.plist << 'EOF' Labelai.wren.recall-local ProgramArguments /opt/homebrew/bin/node /Users/YOUR_USERNAME/clawd/tools/recall-local/server.js RunAtLoad KeepAlive StandardOutPath/Users/YOUR_USERNAME/clawd/tools/recall-local/recall.log StandardErrorPath/Users/YOUR_USERNAME/clawd/tools/recall-local/recall.log EOF # Replace YOUR_USERNAME, then load it launchctl load ~/Library/LaunchAgents/ai.wren.recall-local.plist ``` ### Technical Analysis The documented setup copies an executable JavaScript file into the user's home directory and registers it as a macOS LaunchAgent. The `RunAtLoad` property starts the process whenever the user logs in, while `KeepAlive` directs `launchd` to restart it after termination. This behavior creates cross-session persistence. Persistent execution is not required for the core function of searching local memory files because the server can be started on demand, as the documentation itself demonstrates. Although the LaunchAgent is installed transparently and runs only with the current user's privileges, making it the default setup exceeds the minimum execution lifetime needed for local search. The persistent service executes the mutabl ...[truncated 1193 chars]- Remediation
View remediation
