Back to skill

Security audit

my-computer

Security checks for vulnerabilities and agentic risk

Overview

The skill has a legitimate desktop-automation purpose, but it asks for very broad local authority and includes unsafe file-operation scripts and recurring-task recipes that need careful review.

Install only if you are comfortable giving a skill broad local automation authority. Use it with explicit directories and reviewed commands, prefer dry-runs, do not run undo_operation.sh on manifests you did not create and inspect, and avoid recurring tasks or outbound messages unless the exact schedule, target script, recipients, attachments, and removal steps are shown first.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T06 · System Persistence

Warning
Location
SKILL.md:302
Finding

Persistent Scheduled Task Registration Creates a Durable Execution Channel

Content
View full analysis
~/Library/LaunchAgents/com.user.cleanup-downloads.plist << 'EOF' Label com.user.cleanup-downloads ProgramArguments /bin/bash /Users/me/scripts/cleanup-downloads.sh StartCalendarInterval Hour 9 Minute 0 EOF # Load it launchctl load ~/Library/LaunchAgents/com.user.cleanup-downloads.plist # Add to crontab (crontab -l 2>/dev/null; echo "0 9 * * * /home/user/scripts/cleanup.sh") | crontab - ``` Additional persistent registration examples include: ```bash systemctl --user daemon-reload systemctl --user enable --now cleanup.timer ``` ```powershell schtasks /create /tn "DailyCleanup" /tr "powershell.exe -File C:\scripts\cleanup.ps1" /sc daily /st 09:00 ``` ### Technical Analysis These commands register jobs that remain active after the current Skill invocation and execute scripts in later sessions. Recurring automation is part of the declared Skill functionality, and the Skill separately classifies scheduled-task modification as an operation requiring explicit confirmation. Therefore, the behavior is not hidden or inherently unrelated to the Skill. Nevertheless, the examples establish persistent execution without showing safeguards such as restrictive permissions on the referen ...[truncated 1333 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/undo_operation.sh:37
Finding

Python Code Injection Through an Unescaped Manifest Path

Content
View full analysis
/dev/null || echo "" fi } ``` ### Technical Analysis When `jq` is unavailable, the script interpolates the user-supplied manifest pathname directly into Python source code: ```python d=json.load(open('$MANIFEST')) ``` Shell quoting does not make this safe because the interpolated value becomes part of the Python program passed to `python3 -c`. A manifest filename containing a single quote and valid Python syntax can terminate the string literal and inject additional Python statements. The function also uses `eval` to resolve JSON keys. The keys currently originate from fixed script calls rather than manifest content, but `eval` is unnecessary and increases the fragility and attack surface of the fallback parser. ### Attack Path 1. The target environment has `python3` but does not have `jq`. 2. An attacker creates a valid manifest whose filename contains a Python string terminator and injected Python expression. 3. The attacker convinces the user or automation agent to invoke: ```bash scripts/undo_operation.sh "/path/to/maliciously-named-manifest" ``` 4. `json_get` inserts that pathname into the `python3 -c` program. 5. Python parses and executes the injected expression with the privileges of the user running the undo script. ### Impact Assessment Successful exploitation provides arbitrary Python and operating-system command execution under the invoking user's account. The attacker can read or modify user-accessible files, execute programs, access user ...[truncated 184 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/undo_operation.sh:72
Finding

Untrusted Undo Manifests Permit Arbitrary File Deletion and Relocation

Content
View full analysis
=0; i--)); do if [[ "$JSON_TOOL" == "jq" ]]; then ACTION=$(jq -r ".actions[$i].action" "$MANIFEST") FROM=$(jq -r ".actions[$i].from" "$MANIFEST") TO=$(jq -r ".actions[$i].to" "$MANIFEST") else ACTION=$(python3 -c "import json; d=json.load(open('$MANIFEST')); print(d['actions'][$i]['action'])") FROM=$(python3 -c "import json; d=json.load(open('$MANIFEST')); print(d['actions'][$i]['from'])") TO=$(python3 -c "import json; d=json.load(open('$MANIFEST')); print(d['actions'][$i]['to'])") fi case "$ACTION" in rename|move) # Undo by moving back: to -> from if [[ "$DRY_RUN" == true ]]; then echo " Would move: $TO" echo " back: $FROM" else # Ensure parent directory exists mkdir -p "$(dirname "$FROM")" if mv "$TO" "$FROM" 2>/dev/null; then SUCCESS=$((SUCCESS + 1)) else echo " ERROR: Failed to move $TO -> $FROM" >&2 ERRORS=$((ERRORS + 1)) fi fi ;; copy) # Undo by removing the copy if [[ "$DRY_RUN" == true ]]; then echo " Would delete copy: $TO" else if rm "$TO" 2>/dev/null; then SUCCESS=$((SUCCESS + 1)) else echo " ERROR: Failed to remove $TO" >&2 ERRORS=$((ERRORS + 1)) fi fi ;; ``` ### Technical Analysis The script treats every supplied manifest as authoritative. It does not ...[truncated 1971 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/batch_executor.sh:120
Finding

Unescaped Filenames Corrupt or Inject Undo Manifest Data

Content
View full analysis
/dev/null; then echo "{\"action\":\"rename\",\"from\":\"$filepath\",\"to\":\"$dir/$new_name\"}" >> "$ACTIONS_TMP" return 0 else echo "{\"file\":\"$filepath\",\"error\":\"rename failed\"}" >> "$ERRORS_TMP" return 1 fi ``` ```bash if mv "$filepath" "$target_path" 2>/dev/null; then echo "{\"action\":\"move\",\"from\":\"$filepath\",\"to\":\"$target_path\"}" >> "$ACTIONS_TMP" return 0 else echo "{\"file\":\"$filepath\",\"error\":\"move failed\"}" >> "$ERRORS_TMP" return 1 fi ``` ```bash if cp "$filepath" "$target_path" 2>/dev/null; then echo "{\"action\":\"copy\",\"from\":\"$filepath\",\"to\":\"$target_path\"}" >> "$ACTIONS_TMP" return 0 else echo "{\"file\":\"$filepath\",\"error\":\"copy failed\"}" >> "$ERRORS_TMP" return 1 fi ``` ```bash cat > "$MANIFEST_PATH" << MANIFESTEOF { "operation": "$OPERATION", "source_dir": "$SOURCE_DIR", "timestamp": "$TIMESTAMP", "filter": "$FILTER", "total_files": $TOTAL, "success_count": $SUCCESS_COUNT, "error_count": $ERROR_COUNT, "actions": $ACTIONS_JSON, "errors": $ERRORS_JSON } MANIFESTEOF ``` ### Technical Analysis The manifest is assembled by concatenating paths and command-line values directly into JSON text. JSON requires quotation marks, reverse slashes, control characters, and newlines inside strings to be escaped. The script performs no such encoding. File and directory names on supported systems can contain quotation marks, reverse slashes, tabs, and newlines. Consequently, a specially named source file can terminate a JSON string, introduce additional keys or action object ...[truncated 1713 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (35)

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill’s trigger scope is extremely broad and is explicitly designed to activate on many ordinary requests involving files, apps, compute, scheduling, diagnostics, and cloud workflows. Because this skill has local-machine execution authority, overbroad routing materially increases the chance it is invoked in situations where a narrower, less-privileged skill would be safer, expanding attack surface and the likelihood of unintended destructive actions.

Content

No source excerpt is available for this finding.

Self-Modification

High
Category
Rogue Agent
Confidence
88% confidence
Finding

The skill permits overwriting existing files as a red-tier action rather than prohibiting it by default. In a local automation context, overwrite capability can destroy user data, replace trusted scripts or configs, or facilitate persistence or tampering if the skill is mis-invoked or manipulated.

Content

Scanner excerpt · SKILL.md (reported line 440)May include surrounding context.

md
**Red — always confirm explicitly:**
- Delete files or directories
- Overwrite existing files
- Modify system configuration
- Access directories outside the user's home
- Send emails or messages

Session Persistence

Medium
Category
Rogue Agent
Confidence
94% confidence
Finding

This section introduces creation of launch agents via plist files under ~/Library/LaunchAgents, which is a standard persistence mechanism on macOS. In the context of a local-execution skill, providing persistence recipes increases risk because it enables code to run automatically on a schedule or login, potentially outlasting user awareness of the original task.

Content

Scanner excerpt · SKILL.md (reported line 301)May include surrounding context.

macOS — launchd (preferred over cron):

bash
# Create a plist in ~/Library/LaunchAgents/
cat > ~/Library/LaunchAgents/com.user.cleanup-downloads.plist << 'EOF'
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">

Session Persistence

Medium
Category
Rogue Agent
Confidence
95% confidence
Finding

The explicit 'launchctl load' command operationalizes the persistence mechanism by activating a LaunchAgent. In a desktop automation skill, enabling automatic future execution is dangerous because it can create durable behavior beyond the immediate user interaction and may be abused to rerun scripts or file operations repeatedly.

Content

Scanner excerpt · SKILL.md (reported line 326)May include surrounding context.

EOF

Load it

launchctl load ~/Library/LaunchAgents/com.user.cleanup-downloads.plist

text

**Linux — cron or systemd timers:**

Session Persistence

Medium
Category
Rogue Agent
Confidence
95% confidence
Finding

The explicit 'launchctl load' command operationalizes the persistence mechanism by activating a LaunchAgent. In a desktop automation skill, enabling automatic future execution is dangerous because it can create durable behavior beyond the immediate user interaction and may be abused to rerun scripts or file operations repeatedly.

Content

Scanner excerpt · SKILL.md (reported line 326)May include surrounding context.

EOF

Load it

launchctl load ~/Library/LaunchAgents/com.user.cleanup-downloads.plist

text

**Linux — cron or systemd timers:**

Session Persistence

Medium
Category
Rogue Agent
Confidence
93% confidence
Finding

The skill provides concrete instructions for creating recurring cron jobs, which establishes session persistence on the user’s machine. Persistence is especially sensitive in an automation skill because recurring execution can continue beyond the immediate task and may repeatedly access files, consume resources, or perform unintended actions if created too broadly or deceptively.

Content

Scanner excerpt · SKILL.md (reported line 331)May include surrounding context.

Linux — cron or systemd timers:

bash
# Add to crontab
(crontab -l 2>/dev/null; echo "0 9 * * * /home/user/scripts/cleanup.sh") | crontab -

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
83% confidence
Finding

The skill explicitly includes system-configuration changes within its operating scope, even though it says to confirm first. In a desktop automation skill with command execution capability, encouraging config modification creates a meaningful pathway to privileged or security-sensitive changes that could weaken the host if routing, prompting, or confirmation handling fails.

Content

Scanner excerpt · SKILL.md (reported line 441)May include surrounding context.

md
**Red — always confirm explicitly:**
- Delete files or directories
- Overwrite existing files
- Modify system configuration
- Access directories outside the user's home
- Send emails or messages
- Execute downloaded scripts

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 452)May include surrounding context.

md
- Stay within directories the user points you to. Don't explore `~/` broadly unless asked.
- Never read or expose sensitive files (SSH keys, `.env`, credentials) unless the user explicitly asks.
- Don't install tools or packages without asking. If `exiftool` would help, say "This would work better with exiftool. Want me to install it via Homebrew?"
- Don't modify running application state (kill processes, change preferences) without confirmation.

## Platform Reference

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 486)May include surrounding context.

md
- Stay within directories the user points you to. Don't explore `~/` broadly unless asked.
- Never read or expose sensitive files (SSH keys, `.env`, credentials) unless the user explicitly asks.
- Don't install tools or packages without asking. If `exiftool` would help, say "This would work better with exiftool. Want me to install it via Homebrew?"
- Don't modify running application state (kill processes, change preferences) without confirmation.

## Platform Reference

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 453)May include surrounding context.

md
- Stay within directories the user points you to. Don't explore `~/` broadly unless asked.
- Never read or expose sensitive files (SSH keys, `.env`, credentials) unless the user explicitly asks.
- Don't install tools or packages without asking. If `exiftool` would help, say "This would work better with exiftool. Want me to install it via Homebrew?"
- Don't modify running application state (kill processes, change preferences) without confirmation.

## Platform Reference

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 302)May include surrounding context.

md
open -a "Visual Studio Code" /path/to/project

# Create smart folder search (saved search)
# Smart folders are just XML plist files:
cat > ~/Library/Saved\ Searches/LargeFiles.savedSearch << 'PLIST'
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 304)May include surrounding context.

md
open -a "Visual Studio Code" /path/to/project

# Create smart folder search (saved search)
# Smart folders are just XML plist files:
cat > ~/Library/Saved\ Searches/LargeFiles.savedSearch << 'PLIST'
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 305)May include surrounding context.

md
open -a "Visual Studio Code" /path/to/project

# Create smart folder search (saved search)
# Smart folders are just XML plist files:
cat > ~/Library/Saved\ Searches/LargeFiles.savedSearch << 'PLIST'
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 322)May include surrounding context.

md
open -a "Visual Studio Code" /path/to/project

# Create smart folder search (saved search)
# Smart folders are just XML plist files:
cat > ~/Library/Saved\ Searches/LargeFiles.savedSearch << 'PLIST'
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/app-automation.md (reported line 29)May include surrounding context.

md
open -a "Visual Studio Code" /path/to/project

# Create smart folder search (saved search)
# Smart folders are just XML plist files:
cat > ~/Library/Saved\ Searches/LargeFiles.savedSearch << 'PLIST'
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/app-automation.md (reported line 32)May include surrounding context.

md
open -a "Visual Studio Code" /path/to/project

# Create smart folder search (saved search)
# Smart folders are just XML plist files:
cat > ~/Library/Saved\ Searches/LargeFiles.savedSearch << 'PLIST'
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/app-automation.md (reported line 33)May include surrounding context.

md
open -a "Visual Studio Code" /path/to/project

# Create smart folder search (saved search)
# Smart folders are just XML plist files:
cat > ~/Library/Saved\ Searches/LargeFiles.savedSearch << 'PLIST'
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/app-automation.md (reported line 40)May include surrounding context.

md
open -a "Visual Studio Code" /path/to/project

# Create smart folder search (saved search)
# Smart folders are just XML plist files:
cat > ~/Library/Saved\ Searches/LargeFiles.savedSearch << 'PLIST'
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/app-automation.md (reported line 288)May include surrounding context.

md
open -a "Visual Studio Code" /path/to/project

# Create smart folder search (saved search)
# Smart folders are just XML plist files:
cat > ~/Library/Saved\ Searches/LargeFiles.savedSearch << 'PLIST'
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 304)May include surrounding context.

md
# Create smart folder search (saved search)
# Smart folders are just XML plist files:
cat > ~/Library/Saved\ Searches/LargeFiles.savedSearch << 'PLIST'
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/app-automation.md (reported line 30)May include surrounding context.

md
# Create smart folder search (saved search)
# Smart folders are just XML plist files:
cat > ~/Library/Saved\ Searches/LargeFiles.savedSearch << 'PLIST'
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/app-automation.md (reported line 32)May include surrounding context.

md
# Create smart folder search (saved search)
# Smart folders are just XML plist files:
cat > ~/Library/Saved\ Searches/LargeFiles.savedSearch << 'PLIST'
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/app-automation.md (reported line 41)May include surrounding context.

md
# Create smart folder search (saved search)
# Smart folders are just XML plist files:
cat > ~/Library/Saved\ Searches/LargeFiles.savedSearch << 'PLIST'
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The Mail send and Slack upload recipes perform outbound transmission of message contents and attachments but do not warn about privacy, recipient verification, or external disclosure. In a local automation context, that omission can cause sensitive local files or generated reports to be shared beyond the device with little friction.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The recipes include reading unread Mail inbox contents and extracting browser page text/metadata, both of which can expose personal, corporate, or credential-related information. Because this skill operates directly on a user's machine, examples that access sensitive data without warning or minimization guidance materially increase privacy risk.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dynamic_code_execution

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
scripts/undo_operation.sh:42