Back to skill

Security audit

macOS Disk Cleaner

Security checks for vulnerabilities and agentic risk

Overview

This Mac cleaner has a clear cleanup purpose, but it includes broad permanent deletion workflows that could remove useful user or system data if followed too casually.

Review before installing. Use this only if you are comfortable supervising macOS cleanup closely, and do not let an agent run broad rm -rf or sudo cleanup commands automatically. Prefer preview-only analysis, Finder Trash, Time Machine backups, and exact per-item deletion after you understand the impact.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/safe_delete.py:96
Finding

Arbitrary Permanent Recursive Deletion Without Enforced Safety Boundaries

Content
View full analysis

Vulnerability Details

File Location: scripts/safe_delete.py:96-191
Vulnerability Type: Unsafe arbitrary-path deletion
Risk Level: High

Vulnerable Code

python
# Additional safety check for important paths
path_str = str(path).lower()
danger_patterns = [
    'documents', 'desktop', 'pictures', 'movies',
    'downloads', 'music', '.ssh', 'credentials'
]

if any(pattern in path_str for pattern in danger_patterns):
    print("\n⚠️  WARNING: This path may contain important personal data!")
    print("   Consider backing up before deletion.")

response = input("\nDelete this item? [y/N]: ").strip().lower()
return response == 'y'
python
if response == '' or response == 'none':
    return []
elif response == 'all':
    return items
else:
    selected = []
    # Parse response
    parts = response.replace(' ', '').split(',')

    for part in parts:
        try:
            if '-' in part:
                # Range: 1-5
                start, end = part.split('-')
                start_idx = int(start) - 1
                end_idx = int(end) - 1
                for i in range(start_idx, end_idx + 1):
                    if 0 <= i < len(items):
                        selected.append(items[i])
            else:
                # Single number
                idx = int(part) - 1
                if 0 <= idx < len(items):
                    selected.append(items[idx])
        except ValueError:
            print(f"⚠️  Ignoring invalid selection: {part}")
            continue

    return selected
python
def delete_path(path):
    """
    Delete a file or directory.

    Returns:
        (success, message)
    """
    try:
        path_obj = Path(path)

        if not path_obj.exists():
            return (False, "Path does not exist")

        if path_obj.is_file():
            path_obj.unlink()
        elif 
...[truncated 2719 chars]
Remediation
View remediation

Remediation Suggestions

  1. Canonicalize every target with Path.resolve(strict=True) before applying policy checks.
  2. Reject filesystem roots, the user's home directory itself, system directories, and security-sensitive locations such as ~/.ssh and ~/Library/Keychains.
  3. Compare paths by resolved path components rather than substring matching.
  4. Require the user to type an exact confirmation phrase such as DELETE /resolved/path for sensitive or large targets.
  5. Disable the batch all option whenever the list contains protected, personal-data, credential, or large targets.
  6. Require per-item confirmation for dangerous batch entries.
  7. Implement the active-use, permission, system-path, user-data, and size checks documented in references/safety_rules.md.
  8. Prefer moving files to the macOS Trash so accidental deletion remains recoverable.
  9. Refuse to operate under elevated privileges unless an explicitly documented system-cleanup mode is selected.
  10. Add automated tests covering home-directory deletion, credential paths, system paths, path normalization, batch approval, and large deletions.
Vulnerability Patterns
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (96)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

This second mismatch finding is also valid: the skill claims safe interactive guidance but includes actual deletion workflows, batch deletion concepts, and execution examples beyond mere recommendation. Misleading capability descriptions undermine informed consent and can cause users to approve a skill with greater destructive power than expected.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

This second mismatch finding is also valid: the skill claims safe interactive guidance but includes actual deletion workflows, batch deletion concepts, and execution examples beyond mere recommendation. Misleading capability descriptions undermine informed consent and can cause users to approve a skill with greater destructive power than expected.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill says users should run cleanup commands themselves, but later examples instruct the agent to execute destructive commands directly. Contradictory safety guidance makes it easy for downstream agents to choose the unsafe branch and delete user data autonomously.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 182)May include surrounding context.

md
Scan the following categories systematically. Reference `references/cleanup_targets.md` for detailed explanations.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 1142)May include surrounding context.

md
Scan the following categories systematically. Reference `references/cleanup_targets.md` for detailed explanations.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 218)May include surrounding context.

md
scripts/find_app_remnants.py

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 1134)May include surrounding context.

md
scripts/find_app_remnants.py

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

This duplicate finding identifies the exact command rm -rf ~/.npm/_npx. Even if the target is relatively low value, embedding force-recursive deletion in the skill is unsafe because it conditions downstream systems to perform destructive shell actions directly.

Content

Scanner excerpt · SKILL.md (reported line 297)May include surrounding context.

md
brew cleanup -s

# npm _npx only (safe - temporary packages)
rm -rf ~/.npm/_npx

# pip cache (use with caution)
pip cache purge

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

This duplicate finding identifies the exact command rm -rf ~/.npm/_npx. Even if the target is relatively low value, embedding force-recursive deletion in the skill is unsafe because it conditions downstream systems to perform destructive shell actions directly.

Content

Scanner excerpt · SKILL.md (reported line 297)May include surrounding context.

md
brew cleanup -s

# npm _npx only (safe - temporary packages)
rm -rf ~/.npm/_npx

# pip cache (use with caution)
pip cache purge

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill first warns that many caches are valuable and should generally be preserved, but later recommends blanket deletion of all ~/Library/Caches as 'safe'. Broad recursive cache deletion can disrupt applications, remove offline assets, force large redownloads, and in edge cases destroy stateful app data stored in cache-like paths.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

This duplicate occurrence again recommends rm -rf ~/.npm/_npx in a template context. The risk is consistent: destructive shell deletion is presented as routine and safe without technical safeguards beyond prose.

Content

Scanner excerpt · SKILL.md (reported line 785)May include surrounding context.

md
| 项目 | 大小 | 位置 | 删除后影响 | 清理命令 |
|------|------|------|-----------|---------|
| **废纸篓** | XXX MB | ~/.Trash | 无 - 你已决定删除的文件 | 清空废纸篓 |
| **npm _npx** | X.X GB | ~/.npm/_npx | 下次 npx 命令重新下载 | `rm -rf ~/.npm/_npx` |
| **Homebrew 旧版本** | XX MB | /opt/homebrew | 无 - 已被新版本替代 | `brew cleanup --prune=0` |

**废纸篓内容预览**:

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

This duplicate occurrence again recommends rm -rf ~/.npm/_npx in a template context. The risk is consistent: destructive shell deletion is presented as routine and safe without technical safeguards beyond prose.

Content

Scanner excerpt · SKILL.md (reported line 785)May include surrounding context.

md
| 项目 | 大小 | 位置 | 删除后影响 | 清理命令 |
|------|------|------|-----------|---------|
| **废纸篓** | XXX MB | ~/.Trash | 无 - 你已决定删除的文件 | 清空废纸篓 |
| **npm _npx** | X.X GB | ~/.npm/_npx | 下次 npx 命令重新下载 | `rm -rf ~/.npm/_npx` |
| **Homebrew 旧版本** | XX MB | /opt/homebrew | 无 - 已被新版本替代 | `brew cleanup --prune=0` |

**废纸篓内容预览**:

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

This duplicate occurrence again recommends rm -rf ~/.npm/_npx in a template context. The risk is consistent: destructive shell deletion is presented as routine and safe without technical safeguards beyond prose.

Content

Scanner excerpt · SKILL.md (reported line 785)May include surrounding context.

md
| 项目 | 大小 | 位置 | 删除后影响 | 清理命令 |
|------|------|------|-----------|---------|
| **废纸篓** | XXX MB | ~/.Trash | 无 - 你已决定删除的文件 | 清空废纸篓 |
| **npm _npx** | X.X GB | ~/.npm/_npx | 下次 npx 命令重新下载 | `rm -rf ~/.npm/_npx` |
| **Homebrew 旧版本** | XX MB | /opt/homebrew | 无 - 已被新版本替代 | `brew cleanup --prune=0` |

**废纸篓内容预览**:

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

This is another duplicate use of rm -rf ~/.npm/_npx. Repetition across examples and templates amplifies the likelihood of copy-paste misuse.

Content

Scanner excerpt · SKILL.md (reported line 856)May include surrounding context.

md
# 手动: Finder → 清空废纸篓

# 2. npm _npx (X.X GB)
rm -rf ~/.npm/_npx

# 3. Homebrew 旧版本 (XX MB)
brew cleanup --prune=0

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

This is another duplicate use of rm -rf ~/.npm/_npx. Repetition across examples and templates amplifies the likelihood of copy-paste misuse.

Content

Scanner excerpt · SKILL.md (reported line 856)May include surrounding context.

md
# 手动: Finder → 清空废纸篓

# 2. npm _npx (X.X GB)
rm -rf ~/.npm/_npx

# 3. Homebrew 旧版本 (XX MB)
brew cleanup --prune=0

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
94% confidence
Finding

This duplicate exact match for rm -rf ~/.Trash/* remains dangerous because it uses forceful wildcard deletion in user space. Even commonly deleted content should be presented with preview and safer UX, not irreversible shell removal by pattern.

Content

Scanner excerpt · SKILL.md (reported line 904)May include surrounding context.

md
1. **Empty Trash** (~12 GB)
   - Location: ~/.Trash
   - Command: `rm -rf ~/.Trash/*`

2. **Clear System Caches** (~45 GB)
   - Location: ~/Library/Caches

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
94% confidence
Finding

This duplicate exact match for rm -rf ~/.Trash/* remains dangerous because it uses forceful wildcard deletion in user space. Even commonly deleted content should be presented with preview and safer UX, not irreversible shell removal by pattern.

Content

Scanner excerpt · SKILL.md (reported line 904)May include surrounding context.

md
1. **Empty Trash** (~12 GB)
   - Location: ~/.Trash
   - Command: `rm -rf ~/.Trash/*`

2. **Clear System Caches** (~45 GB)
   - Location: ~/Library/Caches

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
94% confidence
Finding

This duplicate exact match for rm -rf ~/.Trash/* remains dangerous because it uses forceful wildcard deletion in user space. Even commonly deleted content should be presented with preview and safer UX, not irreversible shell removal by pattern.

Content

Scanner excerpt · SKILL.md (reported line 904)May include surrounding context.

md
1. **Empty Trash** (~12 GB)
   - Location: ~/.Trash
   - Command: `rm -rf ~/.Trash/*`

2. **Clear System Caches** (~45 GB)
   - Location: ~/Library/Caches

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

This duplicate exact match for rm -rf ~/Library/Caches/* is a true vulnerability for the same reasons: broad wildcard deletion of app caches is inconsistent with the skill's safety claims and can have widespread unintended effects.

Content

Scanner excerpt · SKILL.md (reported line 908)May include surrounding context.

md
2. **Clear System Caches** (~45 GB)
   - Location: ~/Library/Caches
   - Command: `rm -rf ~/Library/Caches/*`
   - Note: Apps may be slightly slower on next launch

3. **Remove Homebrew Cache** (~5 GB)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

This duplicate exact match for rm -rf ~/Library/Caches/* is a true vulnerability for the same reasons: broad wildcard deletion of app caches is inconsistent with the skill's safety claims and can have widespread unintended effects.

Content

Scanner excerpt · SKILL.md (reported line 908)May include surrounding context.

md
2. **Clear System Caches** (~45 GB)
   - Location: ~/Library/Caches
   - Command: `rm -rf ~/Library/Caches/*`
   - Note: Apps may be slightly slower on next launch

3. **Remove Homebrew Cache** (~5 GB)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

This duplicate exact match for rm -rf ~/Library/Caches/* is a true vulnerability for the same reasons: broad wildcard deletion of app caches is inconsistent with the skill's safety claims and can have widespread unintended effects.

Content

Scanner excerpt · SKILL.md (reported line 908)May include surrounding context.

md
2. **Clear System Caches** (~45 GB)
   - Location: ~/Library/Caches
   - Command: `rm -rf ~/Library/Caches/*`
   - Note: Apps may be slightly slower on next launch

3. **Remove Homebrew Cache** (~5 GB)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

sudo rm -rf /Library/Caches/* combines recursion, force, wildcarding, and root privileges against a system-wide path. This materially raises the blast radius from user inconvenience to system-wide instability or application malfunction.

Content

Scanner excerpt · SKILL.md (reported line 1089)May include surrounding context.

⚠️ This operation requires administrator privileges.

Please run this command manually: sudo rm -rf /Library/Caches/*

⚠️ You'll be asked for your password.

text

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

sudo rm -rf /Library/Caches/* combines recursion, force, wildcarding, and root privileges against a system-wide path. This materially raises the blast radius from user inconvenience to system-wide instability or application malfunction.

Content

Scanner excerpt · SKILL.md (reported line 1089)May include surrounding context.

⚠️ This operation requires administrator privileges.

Please run this command manually: sudo rm -rf /Library/Caches/*

⚠️ You'll be asked for your password.

text

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

This duplicate exact match shows the unsafe command in an execution example, making the danger especially concrete. It encourages an autonomous or semi-autonomous agent to run a destructive wildcard deletion as part of standard workflow.

Content

Scanner excerpt · SKILL.md (reported line 1158)May include surrounding context.

md
3. Present findings: "45 GB in ~/Library/Caches"
4. Explain: "These are safe to delete, apps will regenerate them"
5. Ask confirmation
6. Execute: `rm -rf ~/Library/Caches/*`
7. Report: "Recovered 45 GB"

### Example 2: Development Environment Cleanup

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

This duplicate exact match shows the unsafe command in an execution example, making the danger especially concrete. It encourages an autonomous or semi-autonomous agent to run a destructive wildcard deletion as part of standard workflow.

Content

Scanner excerpt · SKILL.md (reported line 1158)May include surrounding context.

md
3. Present findings: "45 GB in ~/Library/Caches"
4. Explain: "These are safe to delete, apps will regenerate them"
5. Ask confirmation
6. Execute: `rm -rf ~/Library/Caches/*`
7. Report: "Recovered 45 GB"

### Example 2: Development Environment Cleanup

Static analysis

Detected: suspicious.destructive_delete_command

Documentation contains a destructive delete command without an explicit confirmation gate.

Warn
Code
suspicious.destructive_delete_command
Location
references/cleanup_targets.md:42

Documentation contains a destructive delete command without an explicit confirmation gate.

Warn
Code
suspicious.destructive_delete_command
Location
references/safety_rules.md:170

Documentation contains a destructive delete command without an explicit confirmation gate.

Warn
Code
suspicious.destructive_delete_command
Location
SKILL.md:1089