Back to skill

Security audit

mac screenshot

Security checks for vulnerabilities and agentic risk

Overview

The skill is for legitimate local macOS screenshots, but its automatic window matching can capture the wrong visible window without explicit confirmation.

Review before installing if you will grant macOS Screen Recording access. Prefer listing matches first and selecting with --index, avoid broad aliases, and inspect any saved screenshot before sharing it into chat.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/capture-window-by-keyword.sh:70
Finding

Overbroad Keyword Matching May Capture an Unintended Window

Content
View full analysis
len(arr): print(f'Error: index {n} out of range (1-{len(arr)}).', file=sys.stderr) raise SystemExit(2) print(arr[n-1]['id']) else: arr.sort(key=lambda x: 0 if str(x.get('sharing')) == '1' else 1) print(arr[0]['id']) ``` ```bash if ! screencapture -x -l "$WINDOW_ID" "$OUTPUT_PATH"; then echo "Error: screencapture failed for window id $WINDOW_ID." >&2 echo "Check Screen Recording permission for the host process in macOS Settings." >&2 exit 4 fi ``` ### Technical Analysis The script expands application keywords into aliases, including very short values such as `wx` and `tg`. It then applies unrestricted substring matching to a combined string containing the window owner and title. Short aliases can match unrelated words or attacker-controlled window titles. When multiple candidates match and the user does not provide `--index`, the script merely prioritizes windows whose sharing state is `1` and captures the first candidate. It does not require an exact application-owner match, compare bundle identifiers, or request confirmation when matching is ambiguous. The order returned by CoreGraphics and the sharing-state flag do not establish that a window is the target intended by the user. A shareable but unrelated window ca ...[truncated 1519 chars]
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 28)May include surrounding context.

md
scripts/capture-window-by-keyword.sh <keyword> [output_path]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 29)May include surrounding context.

md
scripts/capture-window-by-keyword.sh <keyword> [output_path]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

md
scripts/capture-window-by-keyword.sh <keyword> [output_path]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 36)May include surrounding context.

md
scripts/capture-window-by-keyword.sh <keyword> [output_path]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 37)May include surrounding context.

md
scripts/capture-window-by-keyword.sh <keyword> [output_path]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

md
scripts/capture-window-by-keyword.sh <keyword> [output_path]

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.