This skill openly provides Windows desktop automation, but it can run shell commands, capture remote-access credentials, and send WeChat messages or files without clear approval safeguards.
Review before installing. Only use this on a Windows machine you intentionally want an agent to control, and do not let untrusted users invoke it. Require manual confirmation before ToDesk credential capture, WeChat messages, file transfers, app launches, screenshots, or natural-language task execution. Treat saved screenshots and ToDesk codes/passwords as sensitive secrets, and avoid using the open_app fallback with arbitrary text unless it is changed to a strict allowlist.