Back to skill

Security audit

Atu Desktop Control

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed desktop automation skill with powerful screen, keyboard, mouse, window, and clipboard access, but I found no hidden exfiltration, persistence, or deceptive behavior.

Install this only if you want an agent to control your desktop. Before use, close or hide sensitive windows, avoid keeping secrets in the clipboard, prefer region screenshots, verify the active window before typing or hotkeys, avoid --no-failsafe, and consider pinning dependencies before running setup.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
scripts/setup.sh:17
Finding

Unpinned Third-Party Dependencies Create a Supply-Chain Risk

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README advertises powerful desktop automation capabilities including screenshots, keyboard input, clipboard access, and window control without any warning about privacy, consent, or the ability to alter system state. In an agent skill, these features enable collection of sensitive on-screen data and direct interaction with user applications, so presenting them as routine functionality materially increases misuse risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly enables screenshot capture of the user's desktop, which can easily include passwords, personal messages, documents, tokens, or other sensitive on-screen data. The capability itself is expected for a desktop automation skill, but the documentation does not provide a prominent warning, consent expectation, or guidance to limit capture scope, increasing the risk of privacy and data exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Mouse and keyboard automation can trigger unintended clicks, text entry, hotkeys, window closure, file modification, or destructive system actions if the wrong window is focused or coordinates are incorrect. Because this skill offers broad desktop input control, the absence of strong warnings about focus validation, user confirmation, and side effects makes accidental or unsafe system manipulation more likely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Clipboard read access can expose highly sensitive transient data such as passwords, API keys, MFA codes, wallet addresses, or personal content copied by the user. In a desktop-control skill, this is contextually legitimate functionality, but documenting it without a strong warning or consent boundary creates a real risk of inadvertent data access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The screenshot command captures the user's screen and writes the image to disk with no consent prompt, visibility control, or policy gating. In an agent skill whose purpose is desktop automation, this can expose highly sensitive information such as credentials, messages, documents, and tokens, and persistence to a file increases the chance of later exfiltration.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The keyboard typing command can inject arbitrary text into whichever application currently has focus, enabling unintended commands, message sending, form submission, or script execution. In a desktop-control skill, this is especially dangerous because active-window state can change and the skill provides no confirmation, target validation, or safety interlock before input injection.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The clipboard write path, including the unicode typing helper, overwrites clipboard contents without notifying the user and temporarily stores typed text in the clipboard. This can destroy user data, leak sensitive text into clipboard history managers, and create race conditions where another process reads the temporary clipboard contents before restoration.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The window close command can terminate an application without confirmation, potentially causing data loss if unsaved work is present or interrupting security-critical workflows. Within a full desktop automation skill, such destructive control is more dangerous because actions may be chained or triggered on loosely matched windows.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The clipboard read operation exposes whatever the user most recently copied, which often includes passwords, API keys, tokens, wallet addresses, personal messages, or confidential business data. Because the skill is designed for automation and returns clipboard contents directly in JSON, it creates a straightforward path for silent data collection and exfiltration.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/setup.sh (reported line 26)May include surrounding context.

sh
if [[ "$OSTYPE" == "linux-gnu"* ]]; then
    echo ""
    echo "Linux detected. You may also need:"
    echo "  sudo apt install python3-tk python3-dev scrot"
    echo "  pip install python-xlib  (for pygetwindow)"
elif [[ "$OSTYPE" == "darwin"* ]]; then
    echo ""

Static analysis

No suspicious patterns detected.