T08 · Insecure Dependencies
- Location
SKILL.md:16- Finding
Unpinned Third-Party Executable Installation Without User-Side Integrity Verification
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed desktop automation tool, but it asks users to install an unpinned native binary and documents cloud-mode shell execution without enough scoping controls.
Review this carefully before installing. Prefer local mode for private tasks, consider disabling cloud-mode shell execution with `mano-cua config --set disable-bash true`, and avoid granting broad desktop permissions unless you trust the upstream binary distribution and understand that cloud mode may transmit screenshots and run local shell actions.
SKILL.md:16Unpinned Third-Party Executable Installation Without User-Side Integrity Verification
SKILL.md:119Cloud Mode Enables Model-Directed Shell Execution Beyond the Minimum GUI-Automation Privilege
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
mano-cua run "Search for openai on Google and open the first result" --local --url "https://www.google.com"
mano-cua run "Search for iphone on Xiaohongshu and open the first post" --local --url "https://www.xiaohongshu.com" --minimize --max-steps 15
mano-cua run "Create a new note titled hello world" --local --app "Notes"
No suspicious patterns detected.