Back to skill

Security audit

clean-desktop

Security checks for vulnerabilities and agentic risk

Overview

The skill has a clear desktop-organizing purpose, but it can move desktop files and create folders without a clearly enforced preview or confirmation step.

Review this skill before installing. It should be used only if you are comfortable with an agent moving files on your Desktop; require a preview listing exact source and destination paths before applying changes, and do not allow overwrites or bulk moves without explicit confirmation.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:8
Finding

Dry-Run Safety Control Is Declared but Not Enforced

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 8–19
Vulnerability Type: Missing enforcement of a filesystem safety control
Risk Level: Medium

Vulnerable Instruction Snippet

The following is an English translation of the complete relevant instruction segment:

markdown
## Parameters
- dry_run: Boolean, defaults to true. If true, only preview and do not perform actual operations.

## Execution Flow
1. Obtain the Desktop path (Windows: ~/Desktop, macOS/Linux: ~/Desktop)
2. List all files, excluding .DS_Store and shortcuts
3. Classify by extension:
   - Images: .jpg, .png, .gif → move to Desktop/Images
   - Documents: .pdf, .docx, .txt → move to Desktop/Documents
   - Archives: .zip, .rar → move to Desktop/Archives
4. Generate an operation report informing the user which files were moved

Technical Analysis

The skill declares that dry_run defaults to true and that this mode must only preview operations. However, the execution flow contains no conditional step requiring the agent to evaluate dry_run before creating directories or moving files. Instead, it proceeds directly from file enumeration to instructions to move matching files.

This is a fail-open design: the documented safety parameter exists, but the operative instructions do not bind filesystem mutations to dry_run=false. An agent following the execution flow literally could therefore perform real file moves during the default preview-only mode.

The issue does not demonstrate command injection, privilege escalation, or malicious intent. It is an insecure skill-control implementation because a promised safeguard against unintended filesystem modification is not enforced.

Attack Path

  1. A user invokes the Desktop organization skill without explicitly setting dry_run.
  2. According to the parameter definition, dry_run assumes its default value of true.
  3. The agent enumerates files from the user's Des ...[truncated 1279 chars]
Remediation
View remediation

Remediation Suggestions

  1. Add an explicit conditional branch before every mutating operation:
    • When dry_run=true, only enumerate files and report proposed source and destination paths.
    • When dry_run=false, allow directory creation and file movement.
  2. Require explicit user confirmation before executing the non-dry-run plan, especially when multiple files will be moved.
  3. Ensure that destination directories are not created during dry-run mode because directory creation is also a filesystem mutation.
  4. Define deterministic collision handling. Never overwrite an existing destination file silently; instead, skip the file, request confirmation, or generate a unique filename.
  5. Quote and validate all paths if the workflow is implemented with shell commands. Use argument arrays or equivalent safe filesystem APIs rather than constructing commands through string concatenation.
  6. Generate the report from actual operation results. In dry-run mode, label entries as proposed moves rather than completed moves.
  7. Add test cases verifying that the default invocation performs no writes, directory creation, renaming, or movement.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill describes automatic desktop reorganization and folder creation, which changes user files and filesystem layout, but it does not clearly require explicit user confirmation or prominently warn about these side effects. Even though it says it only moves files and supports dry_run by default, unintended file moves on the desktop can still disrupt user workflows, hide important files, or affect shortcuts and automation that depend on file locations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file describes a registration form that collects team member information and contact details, which are user data that could affect privacy. The document does not include any warning or disclosure about how this information will be stored, used, retained, or protected.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The natural-language instructions and interface text in this skill are presented only in Chinese, which can impose a language constraint on users without documented opt-in. The policy allows locale constraints when choice or justification is provided, but neither appears here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The notification system explicitly includes message push and email notifications, which implies use of user contact information and outbound communication. The document provides no warning that email addresses or related contact data will be used for notifications.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.