Back to skill

Security audit

Macos Desktop Control

Security checks for vulnerabilities and agentic risk

Overview

This macOS desktop-control skill matches much of its purpose, but it includes unsafe persistent command, scheduled task, and sync behavior that needs careful review before installation.

Install only if you are comfortable granting a terminal or agent broad macOS control permissions. Avoid enabling ClawHub sync or cron helpers until the skill uses structured allowlisted actions instead of stored shell scripts, pins dependencies, and adds explicit review before executing or sharing operation records.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Findings (6)

T02 · Agent Memory Poisoning

Error
Location
scripts/operation_search.py:239
Finding

Persistent ControlMemory Records Are Executed as Untrusted Shell Commands

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/natural_language.py:356
Finding

Natural-Language Parameters Are Interpolated into Shell Commands

Content
View full analysis
Remediation
View remediation

T06 · System Persistence

Error
Location
scripts/scheduled_task.sh:44
Finding

Scheduled-Task Interface Installs Arbitrary Persistent Shell Commands

Content
View full analysis
/dev/null | grep -v "mdc-task-" || true; echo "$cron_entry") | crontab - } ``` The stored command is later recovered and evaluated by another shell: ```bash run_task() { local task_id="$1" local task=$(crontab -l 2>/dev/null | grep "mdc-task-$task_id" || true) if [ -n "$task" ]; then local command=$(echo "$task" | sed 's/.*bash //' | sed 's/ # mdc-task-.*//') bash -c "$command" echo "Task completed" else echo "Task not found" fi } ``` ### Technical Analysis The `add` interface accepts both cron schedule text and command text without validating either field. Both values are concatenated into a crontab entry, allowing shell metacharacters and newlines to alter the resulting cron configuration. The task survives the current Skill execution and is run by cron in future sessions. The separate `run` function also retrieves text from crontab and evaluates it with `bash -c`, adding another arbitrary command-execution sink. Scheduled desktop workflows may be a legitimate optional feature, but exposing unrestricted command persistence exceeds the minimum privileges needed for the Skill's declared core functions of screenshots, process listing, system information, clipboard access, and application control. ### Attack Path 1. An attacker convinces the agent or user to invoke the task interface with a malicious command: ```bash bash scripts/scheduled_task.sh add \ "*/5 * * * *" \ ...[truncated 931 chars]
Remediation
View remediation

T06 · System Persistence

Warning
Location
scripts/setup_cron.sh:49
Finding

ClawHub Synchronization Can Be Installed as a Recurring Background Network Task

Content
View full analysis
/dev/null || echo "") # Add new task new_crontab="$current_crontab # ControlMemory sync - every 6 hours 0 0,6,12,18 * * * cd $SCRIPT_DIR && /usr/bin/python3 $SYNC_SCRIPT >> $SCRIPT_DIR/sync.log 2>&1 " # Set crontab echo "$new_crontab" | crontab - ``` The scheduled process connects to a fixed remote service: ```python self.memory_file = self.script_dir / "controlmemory.md" self.sync_state_file = self.script_dir / ".sync_state.json" self.api_base = "https://clawhub.com/api/v1" self.skill_id = "macos-desktop-control" self.api_key = os.getenv('CLAWHUB_API_KEY', '') ``` ```python response = requests.get( f"{self.api_base}/skills/{self.skill_id}/records", headers={'Authorization': f'Bearer {self.api_key}'} if self.api_key else {}, timeout=10 ) ``` ```python response = requests.post( f"{self.api_base}/skills/{self.skill_id}/records", json=record, headers={ 'Authorization': f'Bearer {self.api_key}', 'Content-Type': 'application/json' } if self.api_key else {'Content-Type': 'application/json'}, timeout=10 ) ``` ### Technical Analysis Running `setup_cron.sh` creates a task that survives the current invocation and contacts ClawHub four times per day. This persistence is not necessary for the core desktop-control functionality declared in `SKILL.md` and `package.json`. The current implementation contains incomplete synchronization logic: `get_new_records()` returns an empty list and `update_local_memory()` does nothing. Therefore, the reviewed version does not currently upload parsed ControlMemory records through the normal `sync()` pat ...[truncated 1537 chars]
Remediation
View remediation

other

Note
Location
scripts/control_memory.py:39
Finding

Stable Host-and-Username Fingerprint Is Collected for Contributor Attribution

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:45
Finding

Python Dependencies Are Unpinned and Installed from Mutable Package Index State

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (296)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · API_SETUP_GUIDE.md (reported line 109)May include surrounding context.

创建配置文件:

bash
nano /Users/zhangchangsha/.openclaw/workspace/skills/macos-desktop-control/.env

内容:

Vague Triggers

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

The changelog describes a desktop-control skill that activates from broad natural-language requests like everyday conversational phrases, without any documented scoping, confirmation, or allowlist boundaries. In a powerful macOS control context, ambiguous activation can cause unintended screenshots, app launches/closes, window moves, or automation flows from benign user text or prompt-injected content.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documented command examples include common conversational phrases such as opening apps, closing apps, and starting workflows without any scope constraints or safety gates. Because this skill controls the desktop, these broad phrases increase the risk of accidental execution, misuse via indirect prompt text, and harmful state changes triggered from ordinary language.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

The example code explicitly recommends extending the dispatcher with subprocess.run(..., shell=True), which is dangerous in a natural-language command framework because future developers may interpolate user-derived text into shell commands. That creates a straightforward command-injection path that could execute arbitrary shell commands on the user's macOS system.

Content

Scanner excerpt · CHANGELOG_v1.3.0.md (reported line 206)May include surrounding context.

python
elif action == 'new_action':
    print("执行新动作...")
    subprocess.run("具体命令", shell=True)

支持更多语言

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

The example uses subprocess.run with shell=True and interpolates the app variable directly into the shell command, which enables command injection if app is attacker-controlled or derived from natural-language input. In a desktop-control skill, that is especially dangerous because the whole purpose is to act on user requests, making untrusted input highly likely and potentially leading to arbitrary local command execution.

Content

Scanner excerpt · CHANGELOG_v1.5.0.md (reported line 122)May include surrounding context.

md
# 在 natural_language.py 中
# 成功执行后自动记录
if action == 'app_open':
    subprocess.run(f"open -a '{app}'", shell=True)
    # 记录到 ControlMemory
    memory.record_success(
        app_name=app,

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · CHANGELOG_v1.5.0.md (reported line 140)May include surrounding context.

uage.py 中

成功执行后自动记录

if action == 'app_open': subprocess.run(f"open -a '{app}'", shell=True) # 记录到 ControlMemory memory.record_success( app_name=app, command=f"打开{app}", script=f"open -a '{app}'" )

text

---

### 3. 同步到 ClawHub

```bash
# 手动同步
python3 scripts/clawhub_sync.py

# 自动同步(每小时)
# 配置 crontab
0 * * * * cd /Users/zhangchangsha/.openclaw/workspace/skills/macos-desktop-control && python3 scripts/clawhub_sync.py

🔧 技术实现

架构

text
用户操作
  ↓
自然语言控制
  ↓
执行成功
  ↓
ControlMemory 记录
  ↓
本地存储 (controlmemory.md)
  ↓
ClawHub 同步 (每小时)
  ↓
社区共享

查重算法

python
def is_duplicate(self, new_record):
    """检查是否重复"""
    app = new_record['app']
    command = new_record['command']
    script = new_record['script']
    
    # 检查应用和命令组合
    if f"###

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The plan explicitly expands a local macOS desktop-control skill into a cloud-connected telemetry and sharing system by adding ClawHub upload/download and community synchronization. That materially changes the trust boundary and capability scope from local automation to remote data transfer, which is dangerous because it can exfiltrate user behavior and command contents without that functionality being clearly part of the stated skill purpose.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The sample code stores raw command text in a record object and immediately calls remote synchronization for each new record. This is a concrete exfiltration path: sensitive user input is captured at the point of execution and sent off-device without any shown redaction, review, or explicit user approval.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The ClawHubSync design adds scheduled remote download/upload behavior and merge logic to a skill described as desktop control via native macOS tools. Introducing API-based data transfer and periodic synchronization creates a new exfiltration and supply-chain surface not reflected in the skill metadata, increasing the likelihood that users or reviewers will underestimate the security impact.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documented flow automatically executes previously stored scripts selected by similarity matching, which is dangerous because natural-language similarity is not a security boundary. A stale, poisoned, or overly broad stored operation could be matched to a new request and executed without fresh validation, enabling unintended command execution with system impact.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill heavily guides users to modify macOS privacy settings and grant Accessibility, AppleEvents, and ScreenCapture, but its top-level description does not sufficiently emphasize the sensitivity of those grants or their abuse potential. For a desktop-control tool, broad TCC permissions meaningfully increase the consequences of misuse because they enable observation and control of other apps and on-screen data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill heavily guides users to modify macOS privacy settings and grant Accessibility, AppleEvents, and ScreenCapture, but its top-level description does not sufficiently emphasize the sensitivity of those grants or their abuse potential. For a desktop-control tool, broad TCC permissions meaningfully increase the consequences of misuse because they enable observation and control of other apps and on-screen data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill heavily guides users to modify macOS privacy settings and grant Accessibility, AppleEvents, and ScreenCapture, but its top-level description does not sufficiently emphasize the sensitivity of those grants or their abuse potential. For a desktop-control tool, broad TCC permissions meaningfully increase the consequences of misuse because they enable observation and control of other apps and on-screen data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill heavily guides users to modify macOS privacy settings and grant Accessibility, AppleEvents, and ScreenCapture, but its top-level description does not sufficiently emphasize the sensitivity of those grants or their abuse potential. For a desktop-control tool, broad TCC permissions meaningfully increase the consequences of misuse because they enable observation and control of other apps and on-screen data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill heavily guides users to modify macOS privacy settings and grant Accessibility, AppleEvents, and ScreenCapture, but its top-level description does not sufficiently emphasize the sensitivity of those grants or their abuse potential. For a desktop-control tool, broad TCC permissions meaningfully increase the consequences of misuse because they enable observation and control of other apps and on-screen data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill heavily guides users to modify macOS privacy settings and grant Accessibility, AppleEvents, and ScreenCapture, but its top-level description does not sufficiently emphasize the sensitivity of those grants or their abuse potential. For a desktop-control tool, broad TCC permissions meaningfully increase the consequences of misuse because they enable observation and control of other apps and on-screen data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill heavily guides users to modify macOS privacy settings and grant Accessibility, AppleEvents, and ScreenCapture, but its top-level description does not sufficiently emphasize the sensitivity of those grants or their abuse potential. For a desktop-control tool, broad TCC permissions meaningfully increase the consequences of misuse because they enable observation and control of other apps and on-screen data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The skill heavily guides users to modify macOS privacy settings and grant Accessibility, AppleEvents, and ScreenCapture, but its top-level description does not sufficiently emphasize the sensitivity of those grants or their abuse potential. For a desktop-control tool, broad TCC permissions meaningfully increase the consequences of misuse because they enable observation and control of other apps and on-screen data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill heavily guides users to modify macOS privacy settings and grant Accessibility, AppleEvents, and ScreenCapture, but its top-level description does not sufficiently emphasize the sensitivity of those grants or their abuse potential. For a desktop-control tool, broad TCC permissions meaningfully increase the consequences of misuse because they enable observation and control of other apps and on-screen data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill heavily guides users to modify macOS privacy settings and grant Accessibility, AppleEvents, and ScreenCapture, but its top-level description does not sufficiently emphasize the sensitivity of those grants or their abuse potential. For a desktop-control tool, broad TCC permissions meaningfully increase the consequences of misuse because they enable observation and control of other apps and on-screen data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill heavily guides users to modify macOS privacy settings and grant Accessibility, AppleEvents, and ScreenCapture, but its top-level description does not sufficiently emphasize the sensitivity of those grants or their abuse potential. For a desktop-control tool, broad TCC permissions meaningfully increase the consequences of misuse because they enable observation and control of other apps and on-screen data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill heavily guides users to modify macOS privacy settings and grant Accessibility, AppleEvents, and ScreenCapture, but its top-level description does not sufficiently emphasize the sensitivity of those grants or their abuse potential. For a desktop-control tool, broad TCC permissions meaningfully increase the consequences of misuse because they enable observation and control of other apps and on-screen data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The skill heavily guides users to modify macOS privacy settings and grant Accessibility, AppleEvents, and ScreenCapture, but its top-level description does not sufficiently emphasize the sensitivity of those grants or their abuse potential. For a desktop-control tool, broad TCC permissions meaningfully increase the consequences of misuse because they enable observation and control of other apps and on-screen data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill heavily guides users to modify macOS privacy settings and grant Accessibility, AppleEvents, and ScreenCapture, but its top-level description does not sufficiently emphasize the sensitivity of those grants or their abuse potential. For a desktop-control tool, broad TCC permissions meaningfully increase the consequences of misuse because they enable observation and control of other apps and on-screen data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill heavily guides users to modify macOS privacy settings and grant Accessibility, AppleEvents, and ScreenCapture, but its top-level description does not sufficiently emphasize the sensitivity of those grants or their abuse potential. For a desktop-control tool, broad TCC permissions meaningfully increase the consequences of misuse because they enable observation and control of other apps and on-screen data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.