T06 · System Persistence
- Location
SKILL.md:231- Finding
Persistent Hourly Synchronization Automation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 231-232
Vulnerability Type: Persistent scheduled task
Risk Level: HighVulnerable Source Excerpt
The source instructs the user or Agent to:
text 1. Create the synchronization script ~/.workbuddy/scripts/sync-onedrive.ps1 to synchronize five core files bidirectionally based on modification time. 2. Create a WorkBuddy automation that executes the script every hour.Technical Analysis
The Skill directs the creation of a PowerShell script followed by recurring hourly WorkBuddy automation. This automation survives the initiating Skill run and executes in later sessions under the user's account.
The synchronization script itself is not included in the audited package. Consequently, its final implementation, path validation, conflict behavior, and command safety cannot be verified. The recurring job also creates a durable execution point: modifying the local script after registration could change what is executed each hour.
The persistence is related to synchronization, but an hourly background task is not the minimum privilege necessary. Explicit, user-initiated synchronization would provide the core functionality without creating a cross-session execution mechanism.
Attack Path
- A user invokes the fallback synchronization setup.
- The Agent creates
~/.workbuddy/scripts/sync-onedrive.ps1. - WorkBuddy registers automation that executes the script every hour.
- An attacker who gains write access to the script, its parent directory, or another input interpreted by the script modifies its behavior.
- The registered automation executes the modified behavior repeatedly under the user's account.
- Execution continues across WorkBuddy sessions until the automation is explicitly removed.
Impact Assessment
Successful exploitation provides recurring command execution with the privileges of the WorkBuddy user. The access ...[truncated 345 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the instruction to create recurring hourly automation.
- Use explicit, user-initiated synchronization by default.
- If scheduling is essential, include the complete script in the reviewed package rather than generating an unaudited script dynamically.
- Restrict the script to an allowlisted synchronization directory and fixed filenames.
- Validate canonical source and destination paths before every file operation.
- Do not execute content obtained from synchronized storage.
- Protect the script and automation configuration from modification by unrelated processes.
- Record and verify a cryptographic hash of the approved script before each scheduled execution.
- Require informed user confirmation before registration.
- Document how to inspect, disable, and permanently remove the automation.
