T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:26- Finding
Mandatory Root Execution of Generated or User-Influenced Binaries
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This Linux real-time programming skill is coherent, but it routinely tells users to run generated native code and system-wide tuning commands as root without enough scoping or rollback guidance.
Review before installing. Use this skill only on a dedicated test or real-time machine, not a shared or production workstation. Do not run generated binaries with `sudo` just because the skill says to; prefer unprivileged execution, capabilities, rtprio limits, or targeted device permissions after reviewing the generated C code. Treat GUI shutdown, IRQ affinity changes, and CPU governor writes as explicit administrative actions that need backups, rollback steps, and a clear reason.
SKILL.md:26Mandatory Root Execution of Generated or User-Influenced Binaries
SKILL.md:57Mandatory Inclusion of Disruptive System-Wide Administrative Commands
The pipeline echo performance | sudo tee $cpu combines unprivileged input with privileged file writes, a risky command pattern that normalizes privilege escalation through shell chaining. While the literal input here is fixed, the pattern is still dangerous in an agent skill because it encourages emitting shell constructs that can be easily generalized to unsafe privileged writes and makes review of side effects harder.
cat /sys/devices/system/cpu/cpu*/cpufreq/scaling_governor for cpu in /sys/devices/system/cpu/cpu*/cpufreq/scaling_governor; do echo performance | sudo tee $cpu done
All cores especially isolated real-time cores must report performance governor mode.
The skill’s main output guidance instructs users to compile and run generated real-time code with sudo, but the surrounding guidance does not clearly foreground the risks of privileged execution. In this skill’s context, generated C code may interact with hardware, scheduling, affinity, and memory-mapped I/O, so encouraging routine root execution increases the chance of system instability or unsafe code being run with full privileges.
The skill tells users to execute the produced binary with sudo as part of the default build-and-run flow. Because this assistant can generate or modify C code, normalizing privileged execution of its output creates a direct path for harmful or erroneous code to run with full system permissions.
gcc -O2 -o rt_task your_file.c -lrt -lpthread
sudo ./rt_task
The skill recommends sudo init 3, which immediately terminates the graphical session and changes system runlevel. Even though there is a brief confirmation note, this is still a disruptive privileged command embedded in routine environment guidance and can cause user data loss or service interruption if followed incautiously.
# [CONFIRM BEFORE RUNNING] Immediately terminates graphical session
sudo init 3 # immediate
The skill includes a loop that writes performance to every CPU governor file using sudo tee, applying a system-wide privileged configuration change. This can affect thermals, power consumption, and system behavior across all cores, and the assistant presents it as standard setup rather than a narrowly justified, high-impact administrative action.
cat /sys/devices/system/cpu/cpu*/cpufreq/scaling_governor for cpu in /sys/devices/system/cpu/cpu*/cpufreq/scaling_governor; do echo performance | sudo tee $cpu done
All cores especially isolated real-time cores must report performance governor mode.
The kernel-module and IRQ-affinity guidance discusses request_threaded_irq, ioremap, and binding interrupts to isolated cores without a strong warning that these actions can affect system stability, hang devices, or disrupt interrupt routing. In a Linux RT skill, this is more dangerous than generic systems advice because users are being guided toward low-level kernel and interrupt manipulation where mistakes can degrade or crash the host.
No suspicious patterns detected.