Back to skill

Security audit

Windows Host UI Bridge

Security checks for vulnerabilities and agentic risk

Overview

The skill clearly aims to automate a Windows desktop from WSL2, but it does so through broad host-side shell execution with weak prompt handling and a mutable npm dependency.

Install only if you intentionally want Codex to control your Windows desktop from WSL2. Prefer an exact reviewed package version, a non-shell wrapper or broker, explicit confirmation before each host action, and a constrained Windows account/session with no sensitive apps visible.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Error
Location
SKILL.md:24
Finding

Mutable npm Package Is Downloaded and Executed on the Windows Host

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:17
Finding

Untrusted Prompt Is Interpolated into a Windows Shell Command

Content
View full analysis
``` ### Technical Analysis The skill directly interpolates `action_prompt` into a command string processed by Windows `cmd.exe /C`. It relies on a short denylist rather than a shell-independent argument interface or a complete Windows command-line encoding implementation. Removing only semicolons, ampersands, pipes, dollar signs, and greater-than signs is insufficient for `cmd.exe`. Relevant parsing features not covered by the documented policy include: - Double quotes that can terminate or alter the intended argument boundary. - Percent-delimited environment-variable expansion. - Caret-based escaping and parsing behavior. - Less-than redirection. - Parentheses used in compound command syntax. - Carriage returns and line feeds. - Delayed variable expansion where enabled. - Interactions among WSL argument conversion, `cmd.exe`, and the target program's argument parser. The use of `\"` in the documented WSL command does not provide a general guarantee that arbitrary attacker-controlled text remains one literal argument after all parsing layers. Sanitization is also specified only as an instruction to the agent; no deterministic validation or encoding implementation is included in the project. ### Attack Path 1. Attacker-controlled or untrusted content is accepted as, or incorporated into, `action_prompt`. 2. The agent removes only the five documented denylisted characters. 3. The malicious value retains another Windows shell parsing construct, such as a quote, expansion sequence, control char ...[truncated 1333 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly instructs the agent to invoke Windows host-side cmd.exe and npx from WSL2 to perform UI automation, but it does not require an explicit user-facing warning or confirmation that actions will occur on the host OS outside the current Linux environment. This materially increases the risk of unexpected host manipulation, unintended clicks/keystrokes, and execution of host-side tooling with the user's Windows privileges; the claimed input cleaning is not a sufficient safeguard because the core issue is cross-boundary host control itself.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The instructional content is primarily written in Chinese, including operational requirements such as '此技能专门用于...' and the execution/safety guidance, with no indication that users may choose another language. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless clearly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.