Back to skill

Security audit

Doorstep Screen Control - 屏幕操控

Security checks for vulnerabilities and agentic risk

Overview

This screen-control skill is mostly upfront about desktop automation, but it also documents persistent node installation and local script execution without enough scoping, revocation, or privilege guidance.

Install only if you intentionally want an agent to see your screen and control your mouse and keyboard. Prefer the foreground loopback node run mode, avoid the administrator service install unless you have a clear operational need, and confirm how to stop the node, revoke pairings, and restrict local exec before using it on sensitive systems.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T06 · System Persistence

Error
Location
references/setup-guide.md:19
Finding

Administrator-Level Persistent OpenClaw Node Service

Content
View full analysis

Vulnerability Details

File Location: references/setup-guide.md:19-23
Vulnerability Type: Persistent privileged service installation
Risk Level: High

Vulnerable Code

powershell
openclaw node install --host 127.0.0.1 --port 18789

Technical Analysis

The setup guide presents installation of the OpenClaw Node as a service from an administrator PowerShell session. A system service persists after the initiating terminal closes and can remain active across user logouts and system restarts.

Persistent service installation is not necessary for the Skill's core screenshot, OCR, mouse, and keyboard automation features. The guide already documents a less-privileged foreground alternative:

bash
openclaw node run --host 127.0.0.1 --port 18789

The installed node exposes capabilities that the same guide describes as screen capture, keyboard and mouse control, and local script execution. Although the configured address is restricted to localhost, pairing a controller with this persistent node creates a durable control channel. A compromised paired controller, Gateway, or local process able to access the service could consequently exercise these capabilities beyond the session in which the user intended to run the Skill.

Attack Path

  1. A user follows the documented second setup method and opens PowerShell with administrator privileges.
  2. The user runs the documented openclaw node install command.
  3. OpenClaw Node is registered as a persistent service and remains available beyond the current Skill run or terminal session.
  4. A controller is paired with the node through the documented pairing process.
  5. If that paired controller, the local Gateway, or another authorized control component is compromised, the attacker can reconnect to the persistent node.
  6. The attacker can then use the node's documented screen-capture, input-control, and local-execution functionality within the permis ...[truncated 1061 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove persistent service installation from the default setup workflow.
  2. Use the foreground, loopback-bound openclaw node run mode for ordinary Skill execution.
  3. Run the node as an unprivileged user and grant only the operating-system permissions required for screen capture and input automation.
  4. Stop the foreground node automatically when the requested automation task or user session ends.
  5. If persistent installation is operationally required, place it in a separate advanced section and require explicit, informed user consent.
  6. Document the service's account, effective privileges, startup behavior, logs, network listeners, and exact uninstall command.
  7. Require strong authenticated pairing, provide a way to list and revoke paired controllers, and expire inactive pairings.
  8. Keep the listener bound to loopback unless remote access is explicitly required. If remote access is enabled, require encrypted transport, mutual authentication, and host firewall restrictions.
  9. Restrict or disable general local command execution when only screenshot and input-control functions are needed.
  10. Provide a visible status indicator and an emergency mechanism that stops the node and revokes active sessions.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (12)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared purpose is screen control, but the behavior also includes OpenClaw node pairing/state inspection and command-line interaction with node management. This mismatch is dangerous because reviewers and users may approve the skill for benign desktop automation while it also gains infrastructure-management and command-execution capabilities that expand the attack surface.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/node_pair.py (reported line 12)May include surrounding context.

python
import time

def run_cmd(cmd):
    result = subprocess.run(cmd, shell=True, capture_output=True, text=True)
    return result.stdout.strip(), result.stderr.strip(), result.returncode

def main():

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill appears to rely on shell/env-capable operations but does not declare any explicit tool scope or permission boundaries. For a desktop-control skill that can execute local commands and drive UI actions, missing scope declarations increases the chance of over-privileged execution, unintended command access, and unsafe invocation by the agent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases are broad terms such as '操作电脑' and '自动点击', which can match many ordinary user requests and cause the skill to activate unexpectedly. In a skill that can capture screenshots, read screen contents, and control mouse/keyboard, unintended activation materially raises the risk of unauthorized actions or accidental interference with sensitive applications.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The manifest description and examples are presented entirely in Chinese, including trigger phrases and usage guidance, with no indication that the skill supports other languages or that Chinese is a required locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The guide documents screenshot capture, OCR, mouse/keyboard injection, and local execution but provides only operational notes, not clear security/privacy warnings or consent requirements. These functions can expose sensitive on-screen data and alter system state, so lack of prominent warning and safe-use constraints increases the chance of misuse or unsafe deployment.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guide explicitly states that, after pairing, the agent can use exec to run local scripts, which expands the capability from screen observation/input automation into arbitrary code execution on the host. In a remote-control skill, this materially increases risk because an agent or compromised workflow could perform file/system actions beyond visible UI automation, enabling data theft, persistence, or destructive changes.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This Python file includes its module docstring and all visible user-facing messages in Chinese, with no indication that language selection is optional or region-specific. The policy explicitly flags language or locale constraints when a skill forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/node_pair.py (reported line 12)May include surrounding context.

python
import time

def run_cmd(cmd):
    result = subprocess.run(cmd, shell=True, capture_output=True, text=True)
    return result.stdout.strip(), result.stderr.strip(), result.returncode

def main():

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The code captures full-screen images and can save them to disk without any user-facing consent prompt, notice, redaction, or scope limitation. In a screen-control skill, screenshots may contain credentials, personal data, or confidential business information, so silent capture and persistence materially increases privacy and data-exposure risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

These functions provide direct mouse and keyboard control, enabling arbitrary system-affecting actions such as clicking dialogs, typing into terminals, or invoking destructive shortcuts, yet they expose no confirmation, authorization boundary, or action guardrails. In the context of a remote desktop automation skill, this creates a strong abuse path for unintended commands, privilege misuse, or operator error with immediate real-world effects on the host.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The code hard-codes OCR language selection to "chi_sim+eng", which imposes a specific language/locale behavior without user opt-in or configuration. This can violate language-choice policy expectations when the skill is used in broader contexts.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.