Back to skill

Security audit

Linux GUI Control

Security checks for vulnerabilities and agentic risk

Overview

This skill mostly does what it says, but needs review because its screenshot helper can be abused to run commands and its GUI controls can act broadly on the live desktop without clear safeguards.

Review before installing. Use only in a desktop session where broad click/type/window control is acceptable, save work before following pkill instructions, avoid using untrusted text as action arguments, and patch or avoid the screenshot helper until it validates filenames and passes an end-of-options marker to scrot.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/gui_action.sh:29
Finding

Command Execution Through scrot Option Injection

Content
View full analysis
Remediation
View remediation
&2 exit 1 fi scrot -z -- "$1" ;; ``` Additional hardening measures: 1. Confirm that the deployed `scrot` version supports `--` as an end-of-options marker. 2. Restrict screenshots to an approved directory and resolve the destination to a normalized absolute path. 3. Reject control characters, path traversal components, and unexpected filename extensions if callers are not supposed to choose arbitrary paths. 4. Validate the argument count for every action in the wrapper. 5. Run desktop automation under a minimally privileged user account without access to unrelated credentials or sensitive files. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The workflow tells users to kill and relaunch applications with pkill and an accessibility flag, but it omits any warning that terminating applications can interrupt active sessions and cause unsaved work to be lost. This is especially risky in desktop productivity tools because pkill <app> may close multiple matching processes indiscriminately, amplifying availability and integrity impact.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly supports taking screenshots for visual analysis but does not warn that screenshots can capture passwords, tokens, messages, documents, and other sensitive on-screen data. In a GUI automation skill, this increases the risk of inadvertent data exposure because operators may capture and store images from arbitrary applications without considering privacy or handling requirements.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill provides direct instructions for simulated keyboard and mouse input into arbitrary applications without any safety guidance about focus, target verification, destructive shortcuts, or unintended clicks. Because GUI automation acts on the live desktop, a mistaken target window or keystroke can send commands to the wrong application, trigger purchases, delete data, or disclose information.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
71% confidence
Finding

Using nohup <app> --force-renderer-accessibility ... & creates a background process that persists independently of the invoking shell, which can leave modified application instances running beyond the intended task. In this context, the persistence is not overtly malicious, but it can prolong access to application state, consume resources, and make it easier for subsequent actions to interact with a still-running sensitive session unexpectedly.

Content

Scanner excerpt · SKILL.md (reported line 53)May include surrounding context.

Many modern apps (VS Code, Discord, Cider, Chrome) need a flag to expose their UI tree:

bash
pkill <app>
nohup <app> --force-renderer-accessibility > /dev/null 2>&1 &

Tool Reference

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This script directly exposes GUI automation primitives such as mouse clicks, keystroke injection, window activation, and screenshot capture with no built-in confirmation, allowlisting, or safety interlocks. In an agent skill, those capabilities can be used to drive privileged desktop applications, approve dialogs, enter secrets into the wrong window, or manipulate a user's session in ways the user may not notice in time.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The screenshot action allows silent capture of the current desktop to an arbitrary filename without any disclosure or confirmation. In the context of a GUI-control skill, this can expose sensitive on-screen information such as messages, credentials, documents, or tokens if invoked unexpectedly or repeatedly.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.