Back to skill

Security audit

PC Master

Security checks for vulnerabilities and agentic risk

Overview

This skill is coherent for Windows PC control from WSL2, but it gives an agent broad host-control powers with weak safeguards around command parameters, forced app termination, screenshots, and Windows file access.

Review before installing. This skill should only be used if you intentionally want an agent to operate your Windows desktop from WSL2. Treat requests involving app termination, screenshots, file paths, URLs, and arbitrary app names as sensitive; confirm exact targets first and avoid using it with untrusted or pasted command-like input.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:24
Finding

Command Injection Through Unvalidated Windows Command Parameters

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:24-45
Vulnerability Type: OS command injection caused by unvalidated command parameters
Risk Level: High

Vulnerable Code

bash
# Kill by name
/mnt/c/Windows/System32/taskkill.exe /F /IM chrome.exe

# Kill by PID
/mnt/c/Windows/System32/taskkill.exe /F /PID 1234

Launch Applications

bash
# Open a URL in default browser
/mnt/c/Windows/System32/cmd.exe /c "start https://google.com"

# Open an app by name
/mnt/c/Windows/System32/cmd.exe /c "start chrome"
/mnt/c/Windows/System32/cmd.exe /c "start spotify"
/mnt/c/Windows/System32/cmd.exe /c "start notepad"

# Open a file with its default app
/mnt/c/Windows/System32/cmd.exe /c "start C:\\Users\\User\\file.pdf"

# Launch full path
/mnt/c/Windows/System32/cmd.exe /c "start \"\" \"C:\\Program Files\\App\\app.exe\""

Technical Analysis

The Skill instructs the agent to adapt these command templates to user-supplied process names, process identifiers, URLs, application names, and file paths. It does not require validation, canonicalization, allowlisting, or context-appropriate escaping before placing those values into Bash commands or a cmd.exe /c command string.

The process-management examples leave the process name and PID arguments unquoted. If an agent substitutes request text directly into these templates, Bash metacharacters can terminate or extend the intended command.

The application-launch examples introduce a second command interpreter through cmd.exe /c. Quotes interpreted by Bash do not prevent the resulting string from subsequently being parsed by cmd.exe. A value containing command separators or crafted quote characters can therefore alter the command interpreted by Windows rather than remaining a URL, application name, or path.

Although the examples contain static benign values, their documented purpose requires adapting those values to user requests. The a ...[truncated 1513 chars]

Remediation
View remediation

Remediation Suggestions

  1. Do not place raw request text into Bash or cmd.exe /c command strings.
  2. Validate PIDs using a strict positive-integer pattern and verify the selected process name and PID before termination.
  3. Resolve application requests through a fixed allowlist that maps supported names to trusted executable paths. Reject arbitrary executable names unless the user explicitly approves a verified path.
  4. Canonicalize file paths, require them to remain within user-approved directories, and reject control characters, unexpected quotes, and shell metacharacters.
  5. Validate URLs with a structured parser and allow only approved schemes such as https and, where necessary, http.
  6. Prefer structured process-launch APIs that pass an executable and argument array separately instead of invoking cmd.exe /c.
  7. If a command interpreter is unavoidable, apply escaping specifically designed for both the outer Bash context and the inner Windows command context.
  8. Display the resolved executable, process, URL, or canonical file path and obtain explicit confirmation before forced process termination or other destructive operations.
  9. Add explicit instructions that agents must reject parameters containing command separators, redirection operators, newline characters, or unmatched quotes rather than attempting to sanitize ambiguous input.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill documents forceful process termination using taskkill /F without warning that it can immediately terminate applications and discard unsaved work. Because this skill is designed for direct control of the Windows host from WSL2, these commands make destructive host-side actions easy to perform and increase the chance of accidental denial of service or data loss.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly enables full-screen capture and saves the image to disk without any built-in warning, consent check, or guidance about handling sensitive on-screen data. In this skill’s context, screenshots can expose credentials, personal messages, confidential documents, or other sensitive desktop contents, making the omission security-relevant rather than purely usability-related.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.