Back to skill

Security audit

desktop-organizer

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it says by organizing the desktop, but it can automatically move many local files and folders without a clear confirmation step.

Review before installing. This skill may automatically move most files and folders from your desktop after scanning, and its backup examples are not strong enough to guarantee recovery if copying fails. Use it only if you are comfortable with bulk desktop reorganization, and prefer adding a dry-run plus explicit confirmation before any move happens.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:156
Finding

Backup Failure Can Be Mistaken for Success Before Destructive File Operations

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 156–173
Vulnerability Type: Unverified backup operation and unconditional success reporting
Risk Level: Medium

Vulnerable Code

markdown
> 💡 **此步骤仅为展示,无需等待用户确认,直接继续后续步骤。**

### 第三步:备份桌面

**macOS/Linux**:
```bash
BACKUP_DIR="${BACKUP_PREFIX}$(date +%Y%m%d_%H%M%S)"
cp -r "$DESKTOP_PATH/" "$BACKUP_DIR"
echo "备份完成:$BACKUP_DIR"

Windows:

powershell
$BACKUP_DIR = "$BACKUP_PREFIX$(Get-Date -Format 'yyyyMMdd_HHmmss')"
Copy-Item -Path "$DESKTOP_PATH\*" -Destination "$BACKUP_DIR" -Recurse
Write-Host "备份完成:$BACKUP_DIR"

备份成功后才可继续。

text

### Technical Analysis

The Unix and Windows workflows report that the backup completed without checking whether the copy operation succeeded.

The Unix example does not inspect the exit status of `cp`, enable fail-fast behavior, or validate the destination after copying. The PowerShell example does not use `-ErrorAction Stop`, explicitly create and validate the destination, or verify that all source entries were copied. Its wildcard source can also omit hidden items, contradicting the stated requirement to back up the complete desktop.

The workflow subsequently proceeds to bulk file movement. Because the pre-check explicitly requires no user confirmation and the README describes the process as fully automatic, a partial or failed backup can be treated as valid before potentially destructive changes are made.

### Attack Path

1. The desktop contains an unreadable, locked, hidden, or otherwise uncopyable item, or the backup destination cannot be created due to storage or permission errors.
2. `cp` or `Copy-Item` fails or copies only part of the desktop.
3. The next command unconditionally prints a backup-success message.
4. The automated workflow continues to move desktop files and folders.
5. If a move fails, data is accidentally deleted later, or the user attempts restoration, the backup may not contain the required data.

This is primarily a fa
...[truncated 643 chars]
Remediation
View remediation

Remediation Suggestions

  1. Abort immediately when any backup command fails.

    bash
    BACKUP_DIR="${BACKUP_PREFIX}$(date +%Y%m%d_%H%M%S)"
    if ! cp -a -- "$DESKTOP_PATH" "$BACKUP_DIR"; then
        echo "Backup failed; organization aborted." >&2
        exit 1
    fi
    
  2. For PowerShell, create the destination explicitly and convert non-terminating copy errors into terminating errors.

    powershell
    $ErrorActionPreference = "Stop"
    $BACKUP_DIR = "$BACKUP_PREFIX$(Get-Date -Format 'yyyyMMdd_HHmmss')"
    
    try {
        New-Item -ItemType Directory -Path $BACKUP_DIR -ErrorAction Stop | Out-Null
        Get-ChildItem -LiteralPath $DESKTOP_PATH -Force |
            Copy-Item -Destination $BACKUP_DIR -Recurse -Force -ErrorAction Stop
    }
    catch {
        Write-Error "Backup failed; organization aborted: $_"
        exit 1
    }
    
  3. Verify the backup before moving anything. Compare source and destination entry counts and sizes, and use hashes for important regular files where feasible.

  4. Include hidden entries in the backup and avoid wildcard semantics that silently exclude them.

  5. Check available disk space and destination writability before copying.

  6. Print a success message only after the copy and verification stages both complete successfully.

  7. Display the verified backup path and inventory to the user and request confirmation before beginning bulk moves.

  8. Ensure every later move operation also checks errors and stops safely instead of continuing after a partial organization.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 89)May include surrounding context.

md
| 安装包   | `.dmg` `.pkg` `.exe`                         | `{DESKTOP_PATH}/文档/`     |
| 代码文件  | `.py` `.js` `.ts` `.java` `.sh`              | `{DESKTOP_PATH}/文档/`      |

<!-- ✏️ 你可以增删上表中的行,或者改变目标文件夹路径 -->

---

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 89)May include surrounding context.

md
| 安装包   | `.dmg` `.pkg` `.exe`                         | `{DESKTOP_PATH}/文档/`     |
| 代码文件  | `.py` `.js` `.ts` `.java` `.sh`              | `{DESKTOP_PATH}/文档/`      |

<!-- ✏️ 你可以增删上表中的行,或者改变目标文件夹路径 -->

---

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly instructs the agent to continue from scan to backup and bulk file-moving without explicit user confirmation. For a destructive mass file operation, this removes an important human verification step and increases the risk of unintended data movement, workflow disruption, or loss of access to important files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README describes a fully automatic workflow that scans the desktop, backs it up, and moves files/folders, but it does not prominently warn users that nearly all desktop contents may be relocated. In a filesystem-modifying skill, this omission increases the risk of users triggering disruptive bulk changes without understanding the scope, especially because desktop items often include active project folders, shortcuts, or files expected to remain in place.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation explicitly promotes full automation and 'no manual confirmation' for operations that perform bulk filesystem changes. Removing human confirmation for destructive or disruptive actions makes accidental invocation more dangerous and can lead to widespread file reorganization that breaks user workflows even if a backup exists.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file consistently instructs behavior in Chinese, including user-facing descriptions and execution guidance, but does not state that Chinese is optional or limited to a China-specific deployment. Under the language/locale policy, forcing a single language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill mandates that backup must never be skipped, but the Windows backup procedure uses Copy-Item to a timestamped destination without first ensuring the destination directory exists. Depending on PowerShell behavior and the source glob, this can cause backup failure or incomplete backup while the workflow still proceeds to destructive file moves, undermining the core safety guarantee.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The configuration says only desktop root files will be organized, but the procedure also moves root-level folders themselves into another directory. This mismatch can cause broader-than-expected changes to user data layout, especially when users rely on desktop folders remaining in place.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.