T08 · Insecure Dependencies
- Location
scripts/setup.sh:17- Finding
Unpinned Third-Party Dependencies Create a Supply-Chain Risk
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a disclosed desktop automation skill with powerful screen, keyboard, mouse, window, and clipboard access, but I found no hidden exfiltration, persistence, or deceptive behavior.
Install this only if you want an agent to control your desktop. Before use, close or hide sensitive windows, avoid keeping secrets in the clipboard, prefer region screenshots, verify the active window before typing or hotkeys, avoid --no-failsafe, and consider pinning dependencies before running setup.
scripts/setup.sh:17Unpinned Third-Party Dependencies Create a Supply-Chain Risk
The README advertises powerful desktop automation capabilities including screenshots, keyboard input, clipboard access, and window control without any warning about privacy, consent, or the ability to alter system state. In an agent skill, these features enable collection of sensitive on-screen data and direct interaction with user applications, so presenting them as routine functionality materially increases misuse risk.
The skill explicitly enables screenshot capture of the user's desktop, which can easily include passwords, personal messages, documents, tokens, or other sensitive on-screen data. The capability itself is expected for a desktop automation skill, but the documentation does not provide a prominent warning, consent expectation, or guidance to limit capture scope, increasing the risk of privacy and data exposure.
Mouse and keyboard automation can trigger unintended clicks, text entry, hotkeys, window closure, file modification, or destructive system actions if the wrong window is focused or coordinates are incorrect. Because this skill offers broad desktop input control, the absence of strong warnings about focus validation, user confirmation, and side effects makes accidental or unsafe system manipulation more likely.
Clipboard read access can expose highly sensitive transient data such as passwords, API keys, MFA codes, wallet addresses, or personal content copied by the user. In a desktop-control skill, this is contextually legitimate functionality, but documenting it without a strong warning or consent boundary creates a real risk of inadvertent data access.
The screenshot command captures the user's screen and writes the image to disk with no consent prompt, visibility control, or policy gating. In an agent skill whose purpose is desktop automation, this can expose highly sensitive information such as credentials, messages, documents, and tokens, and persistence to a file increases the chance of later exfiltration.
The keyboard typing command can inject arbitrary text into whichever application currently has focus, enabling unintended commands, message sending, form submission, or script execution. In a desktop-control skill, this is especially dangerous because active-window state can change and the skill provides no confirmation, target validation, or safety interlock before input injection.
The clipboard write path, including the unicode typing helper, overwrites clipboard contents without notifying the user and temporarily stores typed text in the clipboard. This can destroy user data, leak sensitive text into clipboard history managers, and create race conditions where another process reads the temporary clipboard contents before restoration.
The window close command can terminate an application without confirmation, potentially causing data loss if unsaved work is present or interrupting security-critical workflows. Within a full desktop automation skill, such destructive control is more dangerous because actions may be chained or triggered on loosely matched windows.
The clipboard read operation exposes whatever the user most recently copied, which often includes passwords, API keys, tokens, wallet addresses, personal messages, or confidential business data. Because the skill is designed for automation and returns clipboard contents directly in JSON, it creates a straightforward path for silent data collection and exfiltration.
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
if [[ "$OSTYPE" == "linux-gnu"* ]]; then
echo ""
echo "Linux detected. You may also need:"
echo " sudo apt install python3-tk python3-dev scrot"
echo " pip install python-xlib (for pygetwindow)"
elif [[ "$OSTYPE" == "darwin"* ]]; then
echo ""
No suspicious patterns detected.