Back to skill

Security audit

application-use

Security checks across malware telemetry and agentic risk

Overview

This skill transparently provides macOS desktop automation, but it gives agents broad ability to control apps, type sensitive data, submit forms, and manipulate Finder without clear confirmation boundaries.

Install only if you trust the external npm package and are comfortable supervising an agent that can control your Mac desktop. Keep sensitive windows closed, avoid having it handle secrets, and require explicit confirmation before submissions, file changes, messages, purchases, or account actions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger description is broad enough to match many ordinary desktop-assistance requests, which can cause this powerful UI automation skill to activate in contexts far beyond narrowly intended use. Because the skill can open apps, click UI elements, type text, and submit actions on macOS, overbroad routing increases the chance of unintended execution of impactful desktop actions.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The documentation explicitly enables UI automation that can fill forms, send keys, scroll, navigate files, and submit actions without any safety guidance, warning, or confirmation boundary for destructive or privacy-sensitive operations. In this context, a general-purpose macOS automation CLI is especially risky because it can be steered to perform real user-environment actions such as submitting web forms, interacting with Finder, or manipulating applications with little friction.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.