Back to skill

Security audit

agent-desktop

Security checks for vulnerabilities and agentic risk

Overview

This skill gives an agent broad desktop-control abilities, but the sensitive capabilities are disclosed, purpose-aligned, and gated by normal macOS permissions or explicit commands.

Install this only if you trust the agent-desktop package and are comfortable granting desktop Accessibility access. Be careful with screenshots, clipboard reads, notification access, force actions, CDP launches, and session traces; use --no-trace or session gc when you do not want local history retained, and avoid full-screen captures unless needed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documentation prominently advertises screenshot capture, UI reading, clipboard management, and notification access but does not present an up-front warning that these operations may expose secrets, personal data, or regulated information. In a desktop-control skill, this omission is security-relevant because operators or upstream agents may invoke sensitive capabilities without informed consent or data-handling constraints.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger list ends with a catch-all condition covering effectively any desktop GUI interaction task, which can cause the skill to auto-activate in far broader contexts than intended. Because this skill can launch apps, take screenshots, read clipboard contents, and interact with arbitrary UI state, overbroad activation increases the chance of unintended access to sensitive applications or data.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
95% confidence
Finding

The skill documents session manifests, persistent session IDs, automatic tracing, screenshot artifacts, refmaps, and shared multi-agent sessions stored under a user directory. Even though some fields are redacted, persistent local traces and screenshots can retain sensitive UI state, workflow history, and potentially confidential visual data, creating a meaningful data-retention and cross-process exposure risk.

Content

Scanner excerpt · SKILL.md (reported line 99)May include surrounding context.

md
- **Strict resolution:** stale refs return `STALE_REF`; duplicate plausible targets return `AMBIGUOUS_TARGET` instead of choosing arbitrarily.
- **Actionability:** every ref-addressed action checks its applicable live visibility, stability, enabled, editability, policy, supported-action, and hit-test requirements under one bounded budget before a single dispatch. Pointer actions focus before their final geometry read, re-resolve moving endpoints, and return `TIMEOUT` with `details.kind: "actionability_timeout"` instead of sending input after the deadline.
- **Headless vs headed:** ref actions are strictly headless by default: semantic accessibility APIs only, with no focus stealing, cursor movement, or synthesized keyboard input. In headed mode, core focuses the exact ref window before dispatch; pointer actions also require a verified target point, while the adapter owns OS delivery. On macOS, `click`, `right-click`, `type`, `clear`, and `scroll` are physical-first; double/triple-click, hover, and drag are physical-only; expand/collapse and other semantic actions remain semantic. Raw `--xy` input has no window identity and never steals focus. `press` is explicit physical keyboard input; held-input commands (`key-down`, `key-up`, `mouse-down`, `mouse-up`) are reserved and fail closed in the stateless CLI.
- **Sessions and tracing:** run `session start` once per task to create a manifest with `trace: on` (default), then pass its returned ID with `--session` or `AGENT_DESKTOP_SESSION`. Use `session start --screenshots` when you need replay artifacts (`artifacts: full`): pre/post-action PNGs and refmap copies under the session trace directory (sensitive — treat exports like screenshots). Commands in that explicit scope record JSONL automatically to per-process segments under `~/.agent-desktop/sessions/<id>/trace/<pid>-<procTs>.jsonl` — no `--trace` on every call. Read traces back with `trace show` (bounded JSON for agents) or `trace export` (single-file HTML for humans)
...[truncated 26 chars]

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 237)May include surrounding context.

Clipboard

text
agent-desktop clipboard-get                     # Read clipboard
agent-desktop clipboard-set "text"              # Write to clipboard
agent-desktop clipboard-clear                   # Clear clipboard

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation explicitly describes dangerous shortcuts and then immediately documents a --force bypass that allows sending blocked combinations such as app quit, lock screen, force-quit UI, or destructive delete chords. In a desktop-control skill, this materially lowers the barrier for an agent or downstream caller to perform disruptive or potentially destructive actions, especially because the docs frame the bypass as available rather than exceptional.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation exposes screenshot capture of app windows and full displays, including base64 return in JSON, without an explicit warning that screenshots may contain passwords, personal data, tokens, messages, or other sensitive on-screen content. In an agent-desktop skill, this is more dangerous than average because the capability is designed for autonomous GUI observation and can silently expand data collection beyond the minimum needed for a task.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/commands-system.md (reported line 281)May include surrounding context.

FlagDefaultDescription
--formattextRepresentation to read: text, auto (richest available: file references, then image, then text), image, file-urls
--outprivate temp fileWhere to write image bytes when --format image/auto resolves to an image; defaults to a private file under the active session's directory, or ~/.agent-desktop/tmp with no active session

Output by format:

json

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

This markdown file includes a workflow that copies UI text via keyboard shortcuts and then reads it with clipboard-get. While the file is instructional, the surrounding section does not warn that clipboard contents may contain sensitive user data or overwrite the user's clipboard state.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.