Back to skill

Security audit

Desktop Monitor Widget

Security checks for vulnerabilities and agentic risk

Overview

The skill is a real desktop system monitor, but it has review-worthy risks because it auto-installs a Python package and runs a localhost web server that can expose more local data than the widget needs.

Install only if you are comfortable running a local web monitor. Prefer installing psutil yourself in a virtual environment, do not run the launcher with sudo, start it from a directory that contains no sensitive files, and avoid enabling the systemd autostart service unless you specifically want persistent startup behavior and know how to remove it.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T06 · System Persistence

Warning
Location
README.md:91
Finding

Optional system-wide persistence exceeds the widget's minimum privilege requirements

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/start.sh:13
Finding

Launcher automatically installs an unpinned dependency into the active Python environment

Content
View full analysis
/dev/null; then echo "正在安装 psutil..." pip3 install psutil --break-system-packages -q 2>/dev/null || pip3 install psutil -q fi ``` ### Technical Analysis The launcher automatically invokes `pip3` when `psutil` is unavailable. The package has no pinned version or integrity hash, so the code installed and executed depends on the package index and pip configuration present at runtime. Python package installation can execute build-system and installation code. Consequently, the script creates a supply-chain execution path before the widget starts. A compromised configured package index, compromised upstream release, or malicious package substitution could result in arbitrary code execution with the launcher's privileges. The `--break-system-packages` option deliberately bypasses protections designed to prevent pip from modifying an operating-system-managed Python environment. Suppressing standard error also obscures installation failures and relevant security warnings. ### Attack Path 1. The user runs `scripts/start.sh` without `psutil` installed. 2. The import check fails. 3. The script invokes pip against the user's configured package indexes without a version or hash constraint. 4. pip downloads and processes the selected package and its dependencies. 5. If the source or resolved artifact is compromised, package build or installation code executes with the current user's privileges. 6. The active Python environment may also be modified in a way that affects other applications. ### Impact Assessment A compromised dependency path could execute arbitrary code with the privileges of the user launching the Skill. If the launcher is improperly run with elevated privileges, the resulting package installation would in ...[truncated 279 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/widget-web.py:239
Finding

Fallback request handling exposes files from the server's working directory

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/widget-web.py:79
Finding

Wildcard CORS permits cross-origin access to local system telemetry

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (19)

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The skill is presented as a simple desktop monitoring widget, but the described implementation also starts a local HTTP server, exposes endpoints, and opens a browser-based interface. This mismatch is dangerous because users and reviewers may grant trust based on the benign description while overlooking additional execution and network behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file presents all user-facing instructions and descriptions in Chinese, and does not indicate that users may choose another language or locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 21)May include surrounding context.

pip3 install psutil

可选:Tkinter 版本需要 (如需使用桌面窗口模式)

sudo apt install python3-tk

text

## 使用方法

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 88)May include surrounding context.

pip3 install psutil

可选:Tkinter 版本需要 (如需使用桌面窗口模式)

sudo apt install python3-tk

text

## 使用方法

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 109)May include surrounding context.

启用服务:

bash
systemctl enable monitor-widget
systemctl start monitor-widget

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
80% confidence
Finding

The skill appears to use network-capable behavior without declaring any tool scope or allowed-tools boundaries. Even if the HTTP server is intended to be local, undeclared network capability expands the attack surface, weakens least-privilege controls, and makes review and containment harder.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill description and usage instructions are entirely in Chinese, including the prescribed invocation phrases, with no indication that other languages are supported or that Chinese is a justified locale requirement. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Broad trigger phrases like asking about system status or resource usage can collide with normal conversation and cause the skill to activate unintentionally. Unintended activation matters more here because the skill may launch UI elements or start local services, producing side effects without clear user intent.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The startup script automatically installs a Python package at runtime even though the skill is presented as a simple desktop monitoring widget. Installing software modifies the host environment, may pull code from remote package indexes, and expands the trust boundary without explicit user approval.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

A system resource display widget does not inherently justify silently fetching and installing packages during execution. This creates unnecessary supply-chain and environment-integrity risk because running the widget can trigger network access and arbitrary third-party code installation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script performs automatic pip installation without an explicit warning or confirmation from the user. In context, this makes the widget more dangerous because a low-risk monitoring tool unexpectedly changes the system and executes package installation logic, which could be abused through package source compromise or misconfiguration.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script presents its title, status text, and console messages in Chinese, which effectively forces a specific language for users regardless of their locale. The policy allows locale constraints when they are opt-in or clearly justified, but this file does not provide such a choice or explanation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script does more than render a local desktop widget: it starts an HTTP server and exposes live host telemetry over a browser-accessible endpoint. Even though it binds to 127.0.0.1, any local process and, with wildcard CORS, any website able to induce requests from the local browser can potentially read this data, which expands exposure beyond a normal desktop-only widget.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The /data endpoint returns system monitoring information and explicitly sets Access-Control-Allow-Origin: *, which permits arbitrary web origins to read the response if they can reach the local service. This weakens the browser's same-origin protections and can enable cross-origin collection of host state such as CPU, memory, disk, uptime, and process count.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest and module docstring describe a desktop monitoring floating widget, which implies the application should launch and show live resource data. However, main() only instantiates MonitorWidget and never calls update_data(), so the monitoring loop and mainloop() in L223-L255 are never reached during normal execution.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script's comments and user-facing echo messages are written in Chinese, which imposes a specific language on the user without offering a choice or documenting a locale-specific requirement. This can violate language or locale policy when no opt-in or justification is provided.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
75% confidence
Finding

The inline output claims '窗口会自动打开浏览器' as part of the script's behavior, yet this shell script contains no browser-launching logic and only executes the Python file. That statement may be true only if the called Python program does it, so within this file the documentation actively overstates what the code shown actually does.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

This code starts a local HTTP server and automatically opens a browser to consume data from it, which is a network operation that transmits system information such as CPU, memory, disk, temperature, uptime, and process count. Although it prints the access URL, there is no explicit warning or disclosure that system telemetry is being served over HTTP.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The module docstring and later UI strings present the skill as Chinese-language by default, with no indication that users can opt into another language or that the widget is intentionally limited to a Chinese-speaking context. This matches the policy concern for language/locale constraints expressed in natural-language content.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.