T08 · Insecure Dependencies
- Location
SKILL.md:24- Finding
Mutable npm Package Is Downloaded and Executed on the Windows Host
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill clearly aims to automate a Windows desktop from WSL2, but it does so through broad host-side shell execution with weak prompt handling and a mutable npm dependency.
Install only if you intentionally want Codex to control your Windows desktop from WSL2. Prefer an exact reviewed package version, a non-shell wrapper or broker, explicit confirmation before each host action, and a constrained Windows account/session with no sensitive apps visible.
SKILL.md:24Mutable npm Package Is Downloaded and Executed on the Windows Host
SKILL.md:17Untrusted Prompt Is Interpolated into a Windows Shell Command
The skill explicitly instructs the agent to invoke Windows host-side cmd.exe and npx from WSL2 to perform UI automation, but it does not require an explicit user-facing warning or confirmation that actions will occur on the host OS outside the current Linux environment. This materially increases the risk of unexpected host manipulation, unintended clicks/keystrokes, and execution of host-side tooling with the user's Windows privileges; the claimed input cleaning is not a sufficient safeguard because the core issue is cross-boundary host control itself.
The instructional content is primarily written in Chinese, including operational requirements such as '此技能专门用于...' and the execution/safety guidance, with no indication that users may choose another language. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless clearly justified.
No suspicious patterns detected.