Back to skill

Security audit

Ghosthand-Skill

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward guide for controlling a local Android automation service, with sensitive screen, clipboard, and notification abilities disclosed as part of that purpose.

Install only if you intend to let an agent operate Ghosthand on an Android device. Keep Ghosthand policy restrictions enabled, avoid using clipboard, notification, or screenshot routes unless the task requires them, and do not share captured screen or notification content without checking for sensitive data.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · resources/references/ghosthand-api-quick-reference.md (reported line 42)May include surrounding context.

md
- `GET /wait` — wait for UI change and inspect settled state
- `POST /wait` — wait for a selector condition
- `GET /clipboard` / `POST /clipboard` — clipboard read/write
- `GET /notify` / `POST /notify` / `DELETE /notify` — notification read/post/cancel

## Rules that matter in practice

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly recommends using /clipboard to read clipboard contents as a transport primitive, but provides no warning that clipboard data may contain passwords, MFA codes, personal messages, or other sensitive information. In an agent-control context, normalizing clipboard access without consent or minimization increases the risk of privacy leakage and over-collection.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill allows reading or posting notifications via /notify without warning that notifications often contain sensitive personal or security-relevant data such as message previews, OTP codes, account alerts, and contact information. This omission can lead agents to access or expose private data beyond what is necessary for the task.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill recommends taking screenshots when 'visual truth is needed' but does not warn that screenshots can capture highly sensitive on-screen information, including credentials, personal messages, financial data, or security prompts. In a mobile-device control skill, encouraging screenshot capture without privacy constraints materially increases the chance of unnecessary sensitive data collection and retention.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Screenshot capture can collect sensitive on-screen information such as messages, financial data, account details, and one-time codes. Because this skill is specifically designed for structured Android control and debugging, the omission of any privacy warning makes it more likely an agent will capture and persist sensitive visual data without appropriate safeguards.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Documenting clipboard read/write as a normal capability without any caution encourages use of a highly sensitive channel that may contain passwords, OTPs, personal messages, or copied secrets. In this skill context, Ghosthand is an agent-facing Android control runtime, so exposing clipboard access to automation materially increases the risk of silent data exfiltration or unintended overwrites.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

Notification read/post/cancel operations affect both privacy and user experience: reads may expose personal or security notifications, while posting or deleting notifications can mislead users or hide important alerts. In an agent-operated device-control runtime, these capabilities are especially sensitive because they enable observation and manipulation of user-visible trust signals.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.