Back to skill

Security audit

MacOS Desktop Control (Mouse, Keyboard, Screenshots)

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent macOS automation tool, but it gives an agent live screen capture plus mouse and keyboard control without enough containment or cleanup for sensitive desktop data.

Review before installing. Use this only in a trusted macOS session where screen contents are safe to capture, and avoid leaving passwords, private messages, customer data, or sensitive documents visible. Expect agent clicks and typed text to affect the live desktop. The publisher should harden screenshot storage with a private randomized temp path, restrictive permissions, exit-status checks, and cleanup after use.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/vision_wrapper.sh:2
Finding

Predictable Temporary File Used for Sensitive Desktop Screenshots

Content
View full analysis

Vulnerability Details

File Location: scripts/vision_wrapper.sh, lines 2–3
Vulnerability Type: Unsafe temporary-file handling
Risk Level: Medium

Complete Code Snippet:

bash
screencapture -x /tmp/claw_view.png
echo "Screenshot captured at /tmp/claw_view.png"

Technical Analysis

The script stores every desktop screenshot at the fixed, globally predictable path /tmp/claw_view.png. Desktop images can contain credentials, private messages, personal information, or other sensitive material.

The script does not create a private temporary directory, apply a restrictive umask, verify that the destination is not a symbolic link or unexpected file type, or remove the image after consumption. Consequently, the screenshot can remain accessible after execution and may be exposed to other local users depending on the resulting file permissions. A local attacker can also prepare or monitor the known path and attempt file-replacement or symbolic-link manipulation, subject to macOS filesystem permissions and the destination-handling behavior of screencapture.

Line 3 prints a success message without checking the exit status of screencapture, which can also mislead callers when capture or file creation fails.

Attack Path

  1. A local attacker learns the constant screenshot path from the publicly available script.
  2. The attacker monitors /tmp/claw_view.png or prepares the path before the skill runs.
  3. An authorized user or agent invokes vision_wrapper.sh while sensitive information is visible.
  4. screencapture writes the desktop image to the predictable location.
  5. If local permissions allow it, the attacker reads or copies the image before it is replaced or manually deleted.
  6. Alternatively, the attacker attempts to manipulate the pre-existing destination, including through a symbolic link or replacement file. The success and consequences of this variant depend on filesystem permissions a ...[truncated 697 chars]
Remediation
View remediation

Remediation Suggestions

  • Set umask 077 before creating any screenshot so newly created files are accessible only to the invoking user.
  • Create a private temporary directory with mktemp -d and store the screenshot under a randomized name inside it.
  • Register a trap to delete the screenshot and temporary directory on normal exit, interruption, or failure.
  • Check the exit status of screencapture and print a success message only after successful capture.
  • Validate that the generated destination remains inside the newly created directory and is not an unexpected symbolic link or file type.
  • Delete the screenshot immediately after the authorized consumer has processed it. If the wrapper cannot control consumption, return the randomized path and require the caller to perform cleanup.
  • Consider avoiding persistent storage entirely by using a protected stream or other ephemeral transfer mechanism if supported.

Example hardened implementation:

bash
#!/bin/bash
set -euo pipefail
umask 077

tmpdir="$(mktemp -d "${TMPDIR:-/tmp}/claw-view.XXXXXX")"
screenshot="$tmpdir/view.png"
trap 'rm -rf -- "$tmpdir"' EXIT HUP INT TERM

if ! screencapture -x "$screenshot"; then
    echo "Screenshot capture failed" >&2
    exit 1
fi

echo "Screenshot captured at $screenshot"
# Keep the process alive only as required for an authorized consumer,
# or transfer/process the image here before the EXIT trap removes it.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill captures the current screen and stores the image at a predictable path in /tmp, but does not disclose the privacy implications of capturing potentially sensitive on-screen data or leaving artifacts on disk. This is dangerous because screenshots may include credentials, personal data, or confidential business information, and temporary storage in a shared or recoverable location can expand exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill exposes synthetic mouse and keyboard control over the active macOS session but does not warn that these actions can alter system state, trigger unintended clicks, send keystrokes to the wrong window, or interact with sensitive applications. In an agent context, omission of this warning increases the risk of unsafe use because operators may not realize the tool can directly manipulate the live desktop rather than a sandboxed environment.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script unconditionally captures a screenshot of the user's screen and saves it to a predictable temporary path, which can expose sensitive on-screen data such as messages, credentials, documents, or tokens. Because no skill purpose or user-facing justification is provided, this screen access is unnecessary and privacy-invasive by default.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script captures on-screen data without any warning, prompt, or consent flow, creating an undisclosed privacy collection mechanism. Even if intended for legitimate vision functionality, silent capture is dangerous because users may not realize sensitive content from any open window is being collected.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.