Back to skill

Security audit

Screen Vision

Security checks for vulnerabilities and agentic risk

Overview

This screen OCR and click tool is coherent, but it automatically installs unverified external software and can capture or click across the user’s macOS session.

Review this skill before installing. Use it only if you are comfortable granting Screen Recording access and allowing real mouse clicks from OCR results. Prefer scoping commands with --app or --region, avoid using it while sensitive information is visible, and do not run the automatic setup unless you trust the upstream GitHub/Homebrew sources or have independently verified the installed binary.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T03 · Remote Payload Retrieval and Execution

Error
Location
setup.sh:19
Finding

Automatic Installation and Execution of an Unverified Remote Binary

Content
View full analysis
/dev/null || bash "${CLAUDE_SKILL_DIR}/setup.sh" ``` `setup.sh:19-22`: ```bash elif [[ "$(uname -m)" == "arm64" ]]; then install_step "Downloading pre-built binary (Apple Silicon)" curl -sL https://github.com/jackyun1024/mac-screen-vision/releases/download/v1.0.0/screen-vision-1.0.0-arm64-macos.tar.gz | tar xz -C /usr/local/bin/ chmod +x /usr/local/bin/screen-vision ``` `setup.sh:50-52`: ```bash if screen-vision has "$(hostname -s)" 2>/dev/null || screen-vision list 2>/dev/null | head -1 | grep -q '\['; then ok "Screen Recording permission granted" else ``` ### Technical Analysis The Skill directs the agent to run setup automatically whenever `screen-vision` is absent. On Apple Silicon systems without Homebrew, the setup script streams a remote archive directly from a personal GitHub release into `tar`, which extracts its contents into `/usr/local/bin`. No cryptographic signature, pinned SHA-256 digest, archive manifest, or extracted-file validation is used. A versioned HTTPS URL protects transport confidentiality and integrity under ordinary conditions, but it does not independently establish the provenance or expected content of the release asset. The pipeline also prevents inspection of the complete archive before extraction. After extraction, the script marks the resulting file executable and invokes `screen-vision` during the permission check. Consequently, content controlled through the external release channel becomes locally executable code without an integrity gate. ### Attack Path 1. The `screen-vision` command is absent from the tar ...[truncated 1300 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
setup.sh:14
Finding

Mutable and Unpinned Third-Party Installation Sources

Content
View full analysis
/dev/null; then install_step "Installing screen-vision via Homebrew" brew install jackyun1024/tap/screen-vision ok "screen-vision installed via Homebrew" ``` `setup.sh:25-29`: ```bash else install_step "Building screen-vision from source (Intel)" TMPDIR=$(mktemp -d) git clone --depth 1 https://github.com/jackyun1024/mac-screen-vision.git "$TMPDIR/sv" cd "$TMPDIR/sv" && swift build -c release ``` `setup.sh:41-44`: ```bash if command -v brew &>/dev/null; then install_step "Installing cliclick via Homebrew" brew install cliclick ok "cliclick installed" ``` ### Technical Analysis The Homebrew installation uses a custom personal tap without pinning a reviewed formula revision or package digest. Homebrew formulae may execute build and installation logic, so compromise of the tap or its upstream artifacts can result in code execution during installation. The Intel fallback performs a shallow clone of the repository's current default branch and immediately runs `swift build`. It does not check out a specific reviewed commit, verify a signed tag, or validate a source archive digest. The code built at installation time can therefore differ from the code that existed when this Skill was audited. The `cliclick` dependency is also installed at whatever version Homebrew resolves at runtime. Although the audit found no evidence that these upstream projects are currently malicious, their mutable and unverified use creates a supply-chain trust boundary outside the audited project. ### Attack Path 1. The required command is missing, causing setup to run. 2. The script selects either the Homebrew or source-build installation path. 3. An attacker compromises the custom tap, upstre ...[truncated 1115 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
setup.sh:19
Finding

Unvalidated Archive Extraction into a Global Executable Directory

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The description advertises OCR and click automation but does not clearly warn that 'tap' performs real UI actions on the user's macOS session. Users may treat it as informational tooling and unintentionally authorize actions that dismiss dialogs, activate buttons, or interact with sensitive applications.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill requires Screen Recording permission and can OCR arbitrary windows or the full screen, but it does not provide a clear privacy warning that on-screen sensitive data may be captured and processed. This can expose passwords, personal messages, financial data, or enterprise information if the tool is invoked on the wrong screen or app.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill maps broad natural-language phrases like 'what's on screen?' and 'click ~' directly to executable OCR and click actions. Because the skill is user-invocable and performs real screen capture and UI interaction, ambiguous trigger phrasing increases the chance of accidental invocation from ordinary conversation or indirect prompt content, leading to unintended screen inspection or clicks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The setup script performs privileged system changes automatically by installing software into /usr/local/bin and fetching code or binaries from external sources without any explicit confirmation, checksum verification, or signature validation. This increases supply-chain and accidental-installation risk: a user may run the script expecting a harmless check, but it can modify the system and trust remote artifacts immediately.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The trigger mapping hard-codes Korean and English example phrases for interpreting user requests, but does not explain whether language selection is optional, configurable, or limited by design. This can create an implicit language policy without clear user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.