T09 · Insecure Skill Coding Practices
- Location
__init__.py:132- Finding
Approval Mode Does Not Protect Several Sensitive Desktop Operations
- Content
View full analysis
Vulnerability Details
File Location:
__init__.py:132-140,__init__.py:198-228, and__init__.py:348-380
Vulnerability Type: Inconsistent authorization enforcement
Risk Level: HighVulnerable Code
python def scroll(self, clicks: int, direction: str = 'vertical', x: Optional[int] = None, y: Optional[int] = None) -> None: if x is not None and y is not None: pyautogui.moveTo(x, y) if direction == 'vertical': pyautogui.scroll(clicks) else: pyautogui.hscroll(clicks) logger.debug(f"Scrolled {direction} {clicks} clicks")python def key_down(self, key: str) -> None: """Press and hold a key without releasing.""" pyautogui.keyDown(key) logger.debug(f"Key down: '{key}'") def key_up(self, key: str) -> None: """Release a held key.""" pyautogui.keyUp(key) logger.debug(f"Key up: '{key}'") def screenshot(self, region: Optional[Tuple[int, int, int, int]] = None, filename: Optional[str] = None): img = pyautogui.screenshot(region=region) if filename: img.save(filename) logger.info(f"Screenshot saved to: {filename}") else: logger.debug(f"Screenshot captured (region={region})") return imgpython def get_from_clipboard(self) -> Optional[str]: try: import pyperclip text = pyperclip.paste() logger.debug(f"Got from clipboard: '{text[:50]}...'") return text except ImportError: logger.error("pyperclip not installed. Run: pip install pyperclip") return None except Exception as e: logger.error(f"Error getting clipboard: {e}") return NoneTechnical Analysis
The controller advertises
require_approval=Trueas a mechanism that requires user confirmation before desktop actions. Mouse movement, clicking, text entry, and ordinary key presses invoke_check_approval(), but several security-sensitive methods do not.The un ...[truncated 1816 chars]
- Remediation
View remediation
Remediation Suggestions
- Invoke
_check_approval()before every operation that reads from or modifies the desktop environment, including screenshots, clipboard access, scrolling, window operations, key holds, and dialogs. - Separate authorization checks by capability, such as
screen_read,clipboard_read,clipboard_write,keyboard_input, andwindow_control. - Make approval mode fail closed. If approval cannot be obtained, the operation should raise an authorization exception rather than silently continuing.
- Require explicit approval for full-screen captures and clipboard reads even when ordinary mouse movements have been preapproved.
- Ensure convenience functions preserve the caller's security configuration instead of creating a default global controller with approval disabled.
- Add unit tests that instantiate the controller with
require_approval=True, mock the approval response, and verify that no underlying PyAutoGUI or clipboard function is reached after denial. - Consider enabling approval mode by default in autonomous workflows and allowing narrowly scoped, time-limited approvals rather than unrestricted access.
- Invoke
