Back to skill

Security audit

Desktop Control

Security checks for vulnerabilities and agentic risk

Overview

This desktop-control skill is coherent, but it needs review because it can control apps, capture screen and clipboard data, and some sensitive actions bypass its advertised approval mode.

Install only if you are comfortable giving the skill broad control over your current desktop session. Keep failsafe enabled, avoid using it around passwords, tokens, private documents, or sensitive clipboard contents, and treat approval mode as incomplete unless the code is fixed.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
__init__.py:129
Finding

Approval Mode Can Be Bypassed by Multiple Privacy-Sensitive and State-Changing Operations

Content
View full analysis
None: """ Scroll mouse wheel. Args: clicks: Scroll amount (+ = up/left, - = down/right) direction: 'vertical' or 'horizontal' x, y: Position to scroll at (None = current position) """ if x is not None and y is not None: pyautogui.moveTo(x, y) if direction == 'vertical': pyautogui.scroll(clicks) else: pyautogui.hscroll(clicks) logger.debug(f"Scrolled {direction} {clicks} clicks") ``` ```python def key_down(self, key: str) -> None: """Press and hold a key without releasing.""" pyautogui.keyDown(key) logger.debug(f"Key down: '{key}'") def key_up(self, key: str) -> None: """Release a held key.""" pyautogui.keyUp(key) logger.debug(f"Key up: '{key}'") ``` ```python def screenshot(self, region: Optional[Tuple[int, int, int, int]] = None, filename: Optional[str] = None): """ Capture screen or region. Args: region: (left, top, width, height) for partial capture filename: Path to save image (None = return PIL Image) Returns: PIL Image object (if filename is None) """ img = pyautogui.screenshot(region=region) if filename: img.save(filename) logger.info(f"Screenshot saved to: {filename}") else: logger.debug(f"Screenshot captured (region={region})") return img ``` ```python def copy_to_clipboard(self, text: str) -> None: """ Copy text to clipboard. Args: text: Text to copy """ try: import pyperclip pyperclip.copy(text) logger.inf ...[truncated 2778 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
__init__.py:153
Finding

Typed and Clipboard Content Is Exposed Through Application Logs

Content
View full analysis
None: """ Type text with configurable speed. Args: text: Text to type interval: Delay between keystrokes (0 = instant) wpm: Words per minute (overrides interval, typical human: 40-80 WPM) """ if wpm is not None: # Convert WPM to interval (assuming avg 5 chars per word) chars_per_second = (wpm * 5) / 60 interval = 1.0 / chars_per_second if self._check_approval(f"type text: '{text[:50]}...'"): pyautogui.write(text, interval=interval) logger.info(f"Typed text: '{text[:50]}{'...' if len(text) > 50 else ''}' (interval={interval:.3f}s)") ``` ```python def copy_to_clipboard(self, text: str) -> None: """ Copy text to clipboard. Args: text: Text to copy """ try: import pyperclip pyperclip.copy(text) logger.info(f"Copied to clipboard: '{text[:50]}...'") except ImportError: logger.error("pyperclip not installed. Run: pip install pyperclip") except Exception as e: logger.error(f"Error copying to clipboard: {e}") def get_from_clipboard(self) -> Optional[str]: """ Get text from clipboard. Returns: Clipboard text, or None if error """ try: import pyperclip text = pyperclip.paste() logger.debug(f"Got from clipboard: '{text[:50]}...'") return text except ImportError: logger.error("pyperclip not installed. Run: pip install pyperclip") return None except Exception as e: logger.error(f"Error getting clipboard: {e}") return None ``` ### Technical Analysis The controller records up to the first 50 ch ...[truncated 1857 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
__init__.py:48
Finding

Documented Coordinate Bounds Protection Is Not Implemented

Content
View full analysis
None: """ Move mouse to absolute screen coordinates. Args: x: X coordinate (pixels from left) y: Y coordinate (pixels from top) duration: Movement time in seconds (0 = instant) smooth: Use smooth movement (cubic bezier) """ if self._check_approval(f"move mouse to ({x}, {y})"): if smooth and duration > 0: pyautogui.moveTo(x, y, duration=duration, tween=pyautogui.easeInOutQuad) else: pyautogui.moveTo(x, y, duration=duration) logger.debug(f"Moved mouse to ({x}, {y}) in {duration}s") ``` ```python def click(self, x: Optional[int] = None, y: Optional[int] = None, button: str = 'left', clicks: int = 1, interval: float = 0.1) -> None: """ Perform mouse click. Args: x, y: Coordinates to click (None = current position) button: 'left', 'right', 'middle' clicks: Number of clicks (1 = single, 2 = double, etc.) interval: Delay between multiple clicks """ position_str = f"at ({x}, {y})" if x is not None else "at current position" if self._check_approval(f"{button} click {position_str}"): pyautogui.click(x=x, y=y, clicks=clicks, interval=interval, button=button) logger ...[truncated 2708 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:618
Finding

Dependency Installation Instructions Use Unpinned Packages Without Integrity Verification

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (19)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill’s declared description emphasizes mouse, keyboard, and screen control, but the documented capabilities also include window enumeration/activation, clipboard read/write access, and user approval prompts that collect input. This mismatch weakens informed consent and makes it easier to hide privacy-impacting or security-relevant behaviors behind a broader automation label, especially in an agent ecosystem where metadata may be used for trust or policy decisions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guide explicitly promotes broad natural-language commands and autonomous interpretation of user intent, which makes activation scope and resulting actions ambiguous. In a desktop-control skill, that ambiguity is dangerous because the agent may open apps, type into unintended windows, or perform unintended actions without clear confirmation boundaries.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation states that the agent takes screenshots and maintains action context, but provides no privacy warning, retention policy, or guidance about sensitive on-screen data. In a desktop automation context, screenshots can capture passwords, personal data, emails, financial information, or corporate secrets, creating meaningful confidentiality risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The guide includes file-opening and save operations as normal autonomous steps without warning that user files may be modified or overwritten. In an automation agent, this can lead to accidental data loss, corruption, or unauthorized modification if the planner infers the wrong file or save destination.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The guide advertises disabling the failsafe and labels it as a performance mode without adequately warning that this removes an important safety control. For autonomous mouse/keyboard control, disabling failsafe increases the risk of runaway actions, loss of user control, unintended system changes, and difficulty interrupting harmful behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The quick reference prominently documents screenshot capture, screen inspection, window enumeration, and clipboard read/write operations without any explicit warning that these actions may expose secrets such as passwords, tokens, personal data, or confidential documents visible on screen or stored in the clipboard. In a desktop automation skill, these capabilities are inherently sensitive because they can be combined with keystrokes and window switching to collect or transfer data from arbitrary applications.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation includes an example creating a controller with failsafe=False and labels it as maximum speed with no safety checks, but it does not pair that guidance with a strong warning about loss of emergency stop protections or accidental uncontrolled input. In a tool that can move the mouse, type, activate windows, and invoke system hotkeys, disabling failsafes materially increases the chance of destructive or hard-to-stop actions if the script targets the wrong window or behaves unexpectedly.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation promotes broad keyboard, mouse, scrolling, drag-and-drop, hotkeys, and window-control actions but does not clearly warn that automation can trigger destructive or unintended system behavior, such as deleting files, submitting forms, launching programs, or interacting with privileged dialogs. Because the skill can directly drive the desktop, misuse or prompt injection in downstream agent flows could convert ordinary automation into harmful system actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill advertises screenshot capture, image recognition, pixel inspection, and clipboard access without a prominent privacy warning that these features can collect sensitive data such as passwords, tokens, personal messages, or proprietary information visible on screen or stored in the clipboard. In a desktop-control skill, these are inherently sensitive capabilities because they can observe user data outside the immediate task context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The scroll method performs live desktop input without calling the approval check used by other input methods. Unapproved scrolling can alter application state, navigate hidden content, accept UI prompts indirectly, or disrupt user activity, especially because this skill is designed for rapid automation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

key_down and key_up send keyboard state changes without any approval gating. Held modifier keys can be combined with subsequent actions to trigger dangerous shortcuts, interfere with the user session, or leave the system in an unexpected input state that causes unintended commands.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Screenshot capture collects potentially sensitive on-screen data, and optional file saving writes that data to disk, yet neither action requires approval or warns the user. In context, this is especially dangerous because desktop screenshots may include credentials, private messages, financial data, or internal documents, enabling surveillance or exfiltration.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Window enumeration and activation broaden the skill from simple desktop input into application discovery and focus manipulation. This allows the skill to inspect the user’s environment and target specific apps, which can facilitate phishing-like automation, interaction with security-sensitive windows, or collection of contextual information not implied by the declared scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

activate_window changes focus to an arbitrary application without approval, which can redirect subsequent input to a sensitive target. Combined with the skill’s mouse and keyboard automation, this enables unintended or deceptive interaction with other applications and can undermine user awareness of what is being controlled.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill includes clipboard read and write functions even though its stated purpose is mouse, keyboard, and screen control. Clipboard access can capture or overwrite sensitive data such as passwords, tokens, copied documents, or cryptocurrency addresses, expanding the skill into data access and exfiltration territory without clear scope disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Clipboard writes modify shared system state without any warning or approval, which can silently replace data the user expects to paste later. This can be abused for deception, workflow interference, or substitution attacks such as replacing copied payment addresses, commands, or links.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The agent automatically captures screenshots before and after each step and stores them in the result structure, which can include sensitive on-screen content such as passwords, emails, tokens, or personal data. In a desktop automation skill, this materially increases privacy and data-exposure risk because capture happens by default during normal task execution without an explicit consent or minimization control.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This step can write screenshots to disk under a filename supplied by the plan, creating persistent copies of potentially sensitive screen contents. Persisting screenshots is riskier than transient capture because files may be accessed later by other users, processes, backups, or logs, and the code does not present a specific warning or confirmation before saving.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The agent opens the system Run dialog, types a command, and presses Enter automatically, which gives it direct control over launching programs based on task-derived input. In a desktop automation context this is especially dangerous because misinterpretation, prompt injection from upstream task sources, or unsafe app names could cause unintended program execution and arbitrary system interaction without a strong user checkpoint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.