Back to skill

Security audit

mano-cua

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed desktop automation tool, but it asks users to install an unpinned native binary and documents cloud-mode shell execution without enough scoping controls.

Review this carefully before installing. Prefer local mode for private tasks, consider disabling cloud-mode shell execution with `mano-cua config --set disable-bash true`, and avoid granting broad desktop permissions unless you trust the upstream binary distribution and understand that cloud mode may transmit screenshots and run local shell actions.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Error
Location
SKILL.md:16
Finding

Unpinned Third-Party Executable Installation Without User-Side Integrity Verification

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:119
Finding

Cloud Mode Enables Model-Directed Shell Execution Beyond the Minimum GUI-Automation Privilege

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 101)May include surrounding context.

bash
mano-cua run "Search for openai on Google and open the first result" --local --url "https://www.google.com"
mano-cua run "Search for iphone on Xiaohongshu and open the first post" --local --url "https://www.xiaohongshu.com" --minimize --max-steps 15
mano-cua run "Create a new note titled hello world" --local --app "Notes"

Examples

Static analysis

No suspicious patterns detected.