Back to skill

Security audit

Cross Terminal Sync

Security checks for vulnerabilities and agentic risk

Overview

The skill is not clearly malicious, but it asks to cloud-sync sensitive WorkBuddy control files and use broad OneDrive access, so users should review it carefully before installing.

Install only if you intentionally want WorkBuddy memory, identity/profile files, skills, projects, and automation data tied to OneDrive. Prefer a pinned and reviewed MCP server version, limit OneDrive permissions to a dedicated sync folder where possible, avoid syncing agent control files unless you trust every device and cloud principal with write access, and document how to disable the hourly automation and revoke OAuth access.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Findings (4)

T06 · System Persistence

Error
Location
SKILL.md:231
Finding

Persistent Hourly Synchronization Automation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 231-232
Vulnerability Type: Persistent scheduled task
Risk Level: High

Vulnerable Source Excerpt

The source instructs the user or Agent to:

text
1. Create the synchronization script ~/.workbuddy/scripts/sync-onedrive.ps1
   to synchronize five core files bidirectionally based on modification time.
2. Create a WorkBuddy automation that executes the script every hour.

Technical Analysis

The Skill directs the creation of a PowerShell script followed by recurring hourly WorkBuddy automation. This automation survives the initiating Skill run and executes in later sessions under the user's account.

The synchronization script itself is not included in the audited package. Consequently, its final implementation, path validation, conflict behavior, and command safety cannot be verified. The recurring job also creates a durable execution point: modifying the local script after registration could change what is executed each hour.

The persistence is related to synchronization, but an hourly background task is not the minimum privilege necessary. Explicit, user-initiated synchronization would provide the core functionality without creating a cross-session execution mechanism.

Attack Path

  1. A user invokes the fallback synchronization setup.
  2. The Agent creates ~/.workbuddy/scripts/sync-onedrive.ps1.
  3. WorkBuddy registers automation that executes the script every hour.
  4. An attacker who gains write access to the script, its parent directory, or another input interpreted by the script modifies its behavior.
  5. The registered automation executes the modified behavior repeatedly under the user's account.
  6. Execution continues across WorkBuddy sessions until the automation is explicitly removed.

Impact Assessment

Successful exploitation provides recurring command execution with the privileges of the WorkBuddy user. The access ...[truncated 345 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the instruction to create recurring hourly automation.
  • Use explicit, user-initiated synchronization by default.
  • If scheduling is essential, include the complete script in the reviewed package rather than generating an unaudited script dynamically.
  • Restrict the script to an allowlisted synchronization directory and fixed filenames.
  • Validate canonical source and destination paths before every file operation.
  • Do not execute content obtained from synchronized storage.
  • Protect the script and automation configuration from modification by unrelated processes.
  • Record and verify a cryptographic hash of the approved script before each scheduled execution.
  • Require informed user confirmation before registration.
  • Document how to inspect, disable, and permanently remove the automation.

T02 · Agent Memory Poisoning

Error
Location
SKILL.md:69
Finding

Cloud-Controlled Agent State, Skills, and Automation Database

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 69-75 and 213-222
Vulnerability Type: Persistent Agent-state poisoning and remotely mutable control files
Risk Level: Critical

Vulnerable Code Snippets

text
~/.workbuddy/skills       → OneDrivePath/WorkBuddySync/mac/skills
~/.workbuddy/projects     → OneDrivePath/WorkBuddySync/mac/projects
~/.workbuddy/MEMORY.md    → OneDrivePath/WorkBuddySync/mac/MEMORY.md
~/.workbuddy/IDENTITY.md  → OneDrivePath/WorkBuddySync/mac/IDENTITY.md
~/.workbuddy/USER.md      → OneDrivePath/WorkBuddySync/mac/USER.md
~/.workbuddy/SOUL.md      → OneDrivePath/WorkBuddySync/mac/SOUL.md
~/.workbuddy/workbuddy.db → OneDrivePath/WorkBuddySync/mac/workbuddy.db
cmd
ren %USERPROFILE%\.workbuddy\MEMORY.md MEMORY.md.bak
mklink %USERPROFILE%\.workbuddy\MEMORY.md "%ONEDRIVE%\WorkBuddySync\windows\MEMORY.md"
ren %USERPROFILE%\.workbuddy\IDENTITY.md IDENTITY.md.bak
mklink %USERPROFILE%\.workbuddy\IDENTITY.md "%ONEDRIVE%\WorkBuddySync\windows\IDENTITY.md"
ren %USERPROFILE%\.workbuddy\USER.md USER.md.bak
mklink %USERPROFILE%\.workbuddy\USER.md "%ONEDRIVE%\WorkBuddySync\windows\USER.md"
ren %USERPROFILE%\.workbuddy\SOUL.md SOUL.md.bak
mklink %USERPROFILE%\.workbuddy\SOUL.md "%ONEDRIVE%\WorkBuddySync\windows\SOUL.md"
ren %USERPROFILE%\.workbuddy\workbuddy.db workbuddy.db.bak
mklink %USERPROFILE%\.workbuddy\workbuddy.db "%ONEDRIVE%\WorkBuddySync\windows\workbuddy.db"

Technical Analysis

The Skill replaces authoritative local Agent files with symbolic links or directory junctions that point into OneDrive. The affected data includes:

  • Persistent memory
  • Agent identity and persona
  • User profile information
  • Installed Skills
  • Project files
  • The WorkBuddy automation database

These files constitute an Agent control plane rather than ordinary synchronization data. Any device, cloud application, account, or collaborator with write access to the ...[truncated 2345 chars]

Remediation
View remediation

Remediation Suggestions

  • Do not synchronize or link authoritative MEMORY.md, IDENTITY.md, SOUL.md, USER.md, installed Skills, or workbuddy.db.
  • Restrict synchronization to a dedicated directory containing user-selected project artifacts.
  • Import remote data as untrusted, read-only material rather than authoritative Agent instructions.
  • Require explicit review and confirmation before promoting imported memories or Skills into local state.
  • Sign approved Skill and Agent-state files and verify signatures before loading them.
  • Maintain local version history and known-good hashes for sensitive control files.
  • Apply least-privilege OneDrive ACLs and prohibit public or organization-wide sharing.
  • Use separate cloud folders and credentials for synchronization rather than granting access to unrelated OneDrive data.
  • Avoid live synchronization of databases. Use application-supported export and import with exclusive locking and schema validation.
  • Alert the user when a remote change affects any control-plane file.

T08 · Insecure Dependencies

Error
Location
SKILL.md:104
Finding

Unpinned Third-Party Package Installed Directly from a Mutable Git Repository

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 104 and 133
Vulnerability Type: Unsafe third-party dependency installation
Risk Level: High

Vulnerable Code Snippet

bash
pip install git+https://github.com/MrFixit96/onedrive-mcp-server.git

The same installation command is provided for both macOS and Windows.

Technical Analysis

The dependency is installed directly from the repository's default branch without an immutable commit identifier, version pin, package hash, or signature verification. The effective package contents can therefore change after this Skill has been reviewed.

pip install may execute package build and installation logic. A compromised repository, maintainer account, dependency chain, or later malicious upstream change could introduce arbitrary code that runs with the installing user's privileges.

The installed server is especially sensitive because it is intended to access OneDrive using OAuth and expose file-search, download, upload, and sharing operations. A malicious update could abuse both local user access and cloud authorization.

Attack Path

  1. The upstream repository or maintainer account is compromised, or the default branch later receives malicious code.
  2. The user runs the documented unpinned pip install command.
  3. pip retrieves the current repository contents rather than a previously reviewed immutable revision.
  4. Malicious build or installation logic executes under the user's account.
  5. The installed server runs in the WorkBuddy environment and may access local files, OAuth tokens, OneDrive data, or MCP requests.
  6. The malicious behavior can steal data, alter cloud files, or return manipulated tool results.

Impact Assessment

Exploitation can provide arbitrary code execution with the privileges of the user performing the installation. Depending on the installed server's runtime access, the affected scope may include:

  • User-r ...[truncated 446 chars]
Remediation
View remediation

Remediation Suggestions

  • Pin the dependency to a specific audited commit hash or exact signed release.
  • Publish and verify cryptographic hashes for all distributed artifacts.
  • Prefer a trusted package registry with reproducible, hash-locked dependencies.
  • Install the server in an isolated virtual environment or container.
  • Review the package's build configuration and transitive dependencies before installation.
  • Disable automatic upgrades from mutable branches.
  • Run the MCP server under a dedicated least-privilege account where practical.
  • Restrict filesystem and network access to only what the server requires.
  • Document the exact version reviewed by the Skill maintainer.

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:143
Finding

Overly Broad OneDrive and Local WorkBuddy Data Access

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 143-149, 313-350, and 493
Vulnerability Type: Excessive cloud and local data permissions
Risk Level: High

Vulnerable Source Excerpts

text
list_files          List files at any OneDrive path
search_files        Search across filenames and file contents
get_file_metadata   Retrieve file size, type, and modification time
download_file       Download files
upload_file         Upload files
create_sharing_link Create sharing links
text
Step 0: Search the local ~/.workbuddy/ directory and workspace diary.
Step 1: Use the MCP search_files operation to search cloud storage directly.
text
OAuth scopes: Files.ReadWrite + User.Read

Technical Analysis

The declared purpose is cross-terminal synchronization and search within WorkBuddySync. However, the documented MCP capabilities include listing arbitrary OneDrive paths, content search, download, upload, and sharing-link creation under a broad Files.ReadWrite scope.

Write permission and sharing-link creation are not required for read-only cross-terminal search. Searching all of ~/.workbuddy/ and workspace diaries can also expose unrelated identity, memory, configuration, and project information rather than limiting access to the project the user requested.

The combination of broad local discovery and broad cloud write access increases the consequences of mistakes, prompt-driven misuse, or compromise of the MCP server. The configuration therefore exceeds minimum privilege for the primary search use case.

Attack Path

  1. The user authorizes the MCP server with broad OneDrive read/write permissions.
  2. WorkBuddy or an attacker-influenced instruction invokes broad local or cloud search.
  3. Sensitive information outside the intended project is discovered through content search.
  4. The MCP server downloads the data, overwrites cloud content, uploads additional m ...[truncated 1110 chars]
Remediation
View remediation

Remediation Suggestions

  • Restrict cloud access to a dedicated WorkBuddySync application directory.
  • Use read-only authorization for search and retrieval workflows.
  • Request write authorization only for a specific user-confirmed upload operation.
  • Remove or disable sharing-link creation unless the user explicitly requests sharing.
  • Require confirmation that identifies the exact source and destination before upload, overwrite, download, or sharing operations.
  • Limit local searches to explicitly selected project directories instead of all of ~/.workbuddy/.
  • Exclude identity, memory, persona, user-profile, credential, and automation files from default searches.
  • Log sensitive MCP operations without recording file contents or OAuth tokens.
  • Bind the MCP endpoint only to loopback, authenticate local clients, and reject requests from other interfaces.
  • Revoke OAuth authorization when the integration is removed or no longer needed.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

YARA rule 'agent_skill_remote_bootstrap_execution': Remote script or code download followed by execution/bootstrap installation [agent_skills]

High
Category
YARA Match
Confidence
95% confidence
Finding

The skill instructs users to install and run code directly from a GitHub repository via 'pip install git+https://...', which is a remote bootstrap pattern that bypasses normal package vetting and pins no reviewed version or hash. In this context, the installed component receives OAuth-backed access to OneDrive files and is integrated into the agent workflow, so a compromised repository, dependency, or update could lead to credential abuse or broad cloud data access.

Content

Scanner excerpt · SKILL.md (reported line 104)May include surrounding context.

MrFixit96/onedrive-mcp-server 是纯用户态 Python 应用:

  • ❌ 不需要管理员权限
  • ❌ 不注册系统服务
  • ❌ 不修改注册表
  • ❌ 不安装证书
  • ✅ 作为普通进程运行,绑定高端口 (>1024)
  • ✅ 使用用户自己的 OS 密钥环存储凭据(不碰系统级安全策略)

公司电脑无管理员权限也可以装。

Mac 安装

bash
# 1. 安装
pip install git+https://github.com/MrFixit96/onedrive-mcp-server.git

# 2. 配置 WorkBuddy MCP(添加到 ~/.workbuddy/mcp.json)
# HTTP 模式最省事,不需要 Azure 应用注册

~/.workbuddy/mcp.json 添加:

json
{
  "mcpServers": {
    "onedrive": {
      "type": "http",
      "url": "http://localhost:3001/mcp"
    }
  }
}

启动 MCP Server:

bash
# HTTP 模式(推荐,零配置 SSO)
onedrive-mcp --http
# 默认端口 3001,WorkBuddy 自动处理 OAuth 认证

Windows 安装

powershell
# 1. 安装(不需要管理员权限)
pip install git+ht

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger description includes broad phrases like '另一台电脑' and '同步 Skill/项目/配置', which can cause the skill to activate in situations where the user did not intend cloud sync or cross-terminal operations. Because the skill can modify local configuration, create links, and encourage cloud-backed synchronization of sensitive files, accidental invocation increases the chance of unintended data exposure or system changes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill promotes syncing WorkBuddy identity, memory, user profile, projects, and configuration into OneDrive/cloud storage without an explicit warning that these files may contain sensitive or confidential information. In context, this is more dangerous because the content includes long-term memory, identity/persona files, and a local database, all of which can leak personal, corporate, or operational data if synced to cloud storage or shared across devices insecurely.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 286)May include surrounding context.

md
# 2. 等待同步(最多 30 秒)
for ($i=0; $i -lt 30; $i++) {
  if (Test-Path $SIGNAL_FILE) {
    $lastWrite = (Get-Item $SIGNAL_FILE).LastWriteTime
    if ($lastWrite -gt (Get-Date).AddSeconds(-5)) {
      Write-Host "OneDrive sync OK"
      break

File System Enumeration

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.

Content

Scanner excerpt · SKILL.md (reported line 402)May include surrounding context.

bash
# Mac(自动检测 OneDrive 路径)
ONEDRIVE=$(ls -d ~/Library/CloudStorage/OneDrive-* 2>/dev/null || ls -d ~/OneDrive* 2>/dev/null | head -1)
echo "=== OneDrive 状态 ===" && pgrep -l "OneDrive" && echo "=== 同步目录 ===" && ls -la "$ONEDRIVE/WorkBuddySync/" && echo "=== 符号链接 ===" && ls -la ~/.workbuddy/ | grep "^l"
powershell

Static analysis

No suspicious patterns detected.