T09 · Insecure Skill Coding Practices
- Location
scripts/desktop_control.py:70- Finding
AppleScript Injection Through Unsanitized Desktop-Control Parameters
- Content
View full analysis
Vulnerability Details
File Location:
scripts/desktop_control.py, lines 70–161
Vulnerability Type: AppleScript injection leading to arbitrary command execution
Risk Level: HighThe following public functions insert caller-controlled values directly into dynamically generated AppleScript source.
Affected Code
Clipboard text — lines 70–73
python def set_clipboard(text): """Set clipboard to given text.""" script = f'set the clipboard to "{text}"' subprocess.run(["osascript", "-e", script], check=True)Application bundle identifier — lines 103–105
python def focus_app(bundle_id): """Bring the given app to foreground.""" subprocess.run(["osascript", "-e", f'tell application "{bundle_id}" to activate'], check=True)Mouse coordinates — lines 111–117
python def move_mouse(x, y): """Move cursor to screen coordinates (x, y).""" script = f''' tell application "System Events" set cursor to POSIX point {x}, {y} end tell ''' subprocess.run(["osascript", "-e", script], check=True)Click coordinates — lines 120–133
python def click(x, y, button="left"): """Perform a mouse click at (x, y).""" down = f''' tell application "System Events" mouse down at POSIX point {x}, {y} end tell ''' up = f''' tell application "System Events" mouse up at POSIX point {x}, {y} end tell ''' subprocess.run(["osascript", "-e", down], check=True) subprocess.run(["osascript", "-e", up], check=True)Keyboard text — lines 149–156
python def type_text(text): """Type the given string.""" script = f''' tell application "System Events" keystrokes "{text}" end tell ''' subprocess.run(["osascript", "-e", script], check=True)Key code — lines 158–161
python def p ...[truncated 3051 chars]- Remediation
View remediation
Remediation Suggestions
-
Never interpolate caller-controlled data into AppleScript source. Use a fixed script and pass values through
osascriptcommand-line arguments:python script = ''' on run argv set the clipboard to item 1 of argv end run ''' subprocess.run(["osascript", "-e", script, str(text)], check=True) -
Use the same argument-passing pattern for keyboard text and bundle identifiers. Retrieve values from
argvinside a fixed AppleScript program rather than constructing source with Python f-strings. -
Validate bundle identifiers. Reject values that do not match a strict format such as:
python r"^[A-Za-z0-9][A-Za-z0-9.-]*$" -
Enforce numeric types for coordinates and key codes. Reject booleans, strings, floating-point values, negative values where unsupported, and values outside documented screen or key-code ranges:
python if not isinstance(x, int) or isinstance(x, bool): raise TypeError("x must be an integer") -
Prefer native Python APIs or trusted automation libraries that represent arguments as typed values rather than executable AppleScript source.
-
Apply least privilege. Grant the hosting process only the macOS Automation, Screen Recording, and Accessibility permissions required for the intended workflow.
-
Add adversarial tests covering quotation marks, backslashes, multiline strings, control characters, AppleScript statement separators, extremely large integers, and strings supplied where integers are expected.
-
Document trust boundaries. Explicitly state that values derived from web content, files, clipboard data, model output, or remote requests must not reach desktop-control functions without validation.
-
