Back to skill

Security audit

Midscene Automations Skills for HarmonyOS

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent HarmonyOS automation helper, but it gives an agent broad real-device control through Bash, unrestricted HDC shell commands, and a mutable runtime npm package.

Review this before installing if you will connect a personal or production HarmonyOS device. Use it only with a trusted npm registry and model provider, avoid sensitive screens unless necessary, prefer explicit user confirmation before any device-changing action, and be especially careful with raw HDC shell commands.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:21
Finding

Mutable Third-Party Package Is Downloaded and Executed at Runtime

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 21; representative command invocations at lines 84–85, 91–93, 99, 105, 115–116, 122–123, 134–145, 151, 160–161, 200–204, and 210–211
Vulnerability Type: Runtime execution of an unpinned third-party dependency
Risk Level: Medium

Vulnerable Code

markdown
Automate HarmonyOS NEXT devices using `npx -y @midscene/harmony@1`.

Representative executable commands include:

bash
npx -y @midscene/harmony@1 connect
npx -y @midscene/harmony@1 connect --deviceId 0123456789ABCDEF
bash
npx -y @midscene/harmony@1 runhdcshell --command "hidumper -s RenderService -a screen"
bash
npx -y @midscene/harmony@1 act --prompt "type hello world in the search field and press Enter"
npx -y @midscene/harmony@1 act --prompt "long press the message bubble and tap Delete in the popup menu"

Technical Analysis

The Skill instructs the agent to execute @midscene/harmony through npx -y. The -y option suppresses the package-installation confirmation, while the version selector @1 permits npm to resolve a changing release within major version 1 rather than an exact, previously audited version.

If the package is unavailable locally, npx can retrieve it from the configured npm registry and execute its CLI code. Package lifecycle scripts may also execute during installation, depending on npm configuration. Consequently, the code that runs can change without any corresponding modification to this repository or SKILL.md.

This creates a supply-chain trust boundary: security depends on the package publisher, publisher credentials, registry configuration, package dependencies, and whichever compatible version is selected at execution time. The repository contains no lockfile or integrity metadata that would ensure the executed artifact is identical to an audited release.

Attack Path

  1. An attacker compromises the package publisher, ...[truncated 1416 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace the mutable major-version selector with an exact, reviewed package version, such as @midscene/harmony@1.x.y.
  2. Prefer installing dependencies through a committed lockfile containing resolved versions and integrity hashes rather than downloading them during every Skill execution.
  3. Use npm ci in a controlled build or preparation phase, then invoke the locally installed binary with npx --no-install or an equivalent package-manager command.
  4. Review the package and its transitive dependency tree before approving upgrades. Apply dependency updates through an explicit review process.
  5. Disable lifecycle scripts during installation where compatible with the package, or inspect and explicitly approve required scripts.
  6. Configure npm to use a trusted registry and protect registry configuration from user-controlled or project-controlled overrides.
  7. Run device automation in a sandbox or dedicated low-privilege account with narrowly scoped filesystem and network access.
  8. Provide only task-specific credentials to the process, rotate exposed credentials, and avoid placing unrelated secrets in its environment.
  9. Limit HDC access to the intended device and disconnect the device when automation is complete.
  10. Document that screenshots and other visual data may be sent to the configured external model provider, and avoid exposing sensitive on-screen information unless explicitly required.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger list includes broad natural-language phrases such as requests to 'test' or 'check' an app on HarmonyOS, which can cause the skill to activate on ordinary user requests that did not explicitly ask for device automation. Because this skill can control a connected device and perform UI actions, overbroad invocation increases the chance of unintended execution on real hardware.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill explicitly exposes raw device-shell execution via runhdcshell forwarded to hdc shell, but it does not provide a clear safety warning, approval boundary, or restriction on destructive/system-affecting commands. In context, this is more dangerous because the skill targets a real connected HarmonyOS device and also recommends fast lower-level control, which could enable app tampering, settings changes, data access, or device disruption if invoked carelessly or through prompt-trigger confusion.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.