Back to skill

Security audit

desktop-control

Security checks for vulnerabilities and agentic risk

Overview

This desktop automation skill is mostly coherent, but it gives agents broad control over the user's computer with incomplete approval checks and weak handling of screenshots, clipboard data, and app-launch commands.

Install only if you are comfortable giving an agent broad desktop-control authority. Keep failsafe enabled, avoid administrator execution, do not use it with passwords or sensitive clipboard contents, and review or restrict any workflow that saves screenshots, reads the clipboard, launches apps, or submits content in external accounts.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
__init__.py:156
Finding

Sensitive typed and clipboard content is written to logs

Content
View full analysis
50 else ''}' " f"(interval={interval:.3f}s)" ) ``` ```python try: import pyperclip pyperclip.copy(text) logger.info(f"Copied to clipboard: '{text[:50]}...'") except ImportError: logger.error("pyperclip not installed. Run: pip install pyperclip") except Exception as e: logger.error(f"Error copying to clipboard: {e}") ``` ```python try: import pyperclip text = pyperclip.paste() logger.debug(f"Got from clipboard: '{text[:50]}...'") return text except ImportError: logger.error("pyperclip not installed. Run: pip install pyperclip") return None except Exception as e: logger.error(f"Error getting clipboard: {e}") return None ``` ### Technical Analysis The controller records the first 50 characters of typed and clipboard content. Desktop automation routinely handles passwords, authentication tokens, recovery codes, private messages, personal data, and other secrets. Logging their plaintext prefixes violates data minimization and creates a secondary copy outside the original application. Typed text and clipboard writes are logged at `INFO` level. Because the module configures logging with `logging.basicConfig(level=logging.INFO)`, these disclosures occur under the default configuration. Clipboard reads use `DEBUG`, but become exposed whenever debugging is enabled by the application. Approval prompts also interpolate typed content into the terminal when `require_approval=True`, which can expose the same sensitive material to terminal history or session capture. ### Attack Path 1. ...[truncated 1098 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
__init__.py:210
Finding

Approval mode can be bypassed for screen, clipboard, and input operations

Content
View full analysis
None: """ Copy text to clipboard. Args: text: Text to copy """ try: import pyperclip pyperclip.copy(text) logger.info(f"Copied to clipboard: '{text[:50]}...'") except ImportError: logger.error("pyperclip not installed. Run: pip install pyperclip") except Exception as e: logger.error(f"Error copying to clipboard: {e}") def get_from_clipboard(self) -> Optional[str]: """ Get text from clipboard. Returns: Clipboard text, or None if error """ try: import pyperclip text = pyperclip.paste() logger.debug(f"Got from clipboard: '{text[:50]}...'") return text except ImportError: logger.error("pyperclip not installed. Run: pip install pyperclip") return None except Exception as e: logger.error(f"Error getting clipboard: {e}") return None ``` O ...[truncated 2036 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
ai_agent.py:375
Finding

Caller-controlled application names can be executed through the Windows Run dialog

Content
View full analysis
None: """Launch an application.""" # Get launch command from knowledge base app_info = self.app_knowledge.get(app, {}) launch_cmd = app_info.get("launch_command", app) # Open Run dialog self.dc.hotkey('win', 'r') time.sleep(0.5) # Type and execute command self.dc.type_text(launch_cmd, wpm=100) self.dc.press('enter') logger.info(f"Launched: {app}") ``` The method is reachable through caller-provided step dictionaries: ```python if step_type == "launch_app": self._do_launch_app(step["app"]) result["success"] = True ``` The guide also documents manual invocation of `_execute_step()` with caller-created step dictionaries. ### Technical Analysis The application knowledge base is used as a lookup, but unknown values are not rejected. Instead, the original `app` string becomes `launch_cmd`: ```python launch_cmd = app_info.get("launch_command", app) ``` That string is entered into the Windows Run dialog and executed. This turns the application-launch feature into a general command-execution channel. The normal natural-language planner currently recognizes known applications and otherwise defaults to Notepad, reducing exposure through `execute_task()`. However, `_execute_step()` accepts arbitrary dictionaries, and manual step execution is explicitly documented. Therefore, any caller able to supply a step can bypass the planner’s limited extraction logic. No shell API is used directly, but the Windows Run dialog provides equivalent execution behavior under the current interactive user account. ### Attack Path 1. An attacker controls or influences a step passed to `_execute_step()`. 2. The attacker supplies a step similar to: ```python { "type": "launch_a ...[truncated 1155 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (26)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The guide documents disabling the failsafe and labels it as a faster mode without emphasizing that this removes a key control against runaway or unsafe automation. In a system that can autonomously click, type, launch apps, and iterate, removing the failsafe can amplify mistakes into uncontrolled destructive actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation recommends a 'maximum speed' mode with failsafe disabled and labels it as having no safety checks, which meaningfully lowers protections against runaway or misdirected automation. Because this skill can control mouse, keyboard, windows, and clipboard, disabling emergency safeguards can lead to destructive clicks, unintended command execution, data loss, or rapid propagation of mistakes before a user can intervene.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description frames the skill as desktop automation, but the documented behavior materially extends into window enumeration/activation, clipboard read/write, interactive approval prompts, and persistent screenshot storage. These extra capabilities increase privacy and control risk because they enable collection of sensitive user context and data beyond what a minimally described automation skill would lead users to expect.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The constructor documentation suggests that enabling require_approval will require user confirmation for actions, but multiple state-changing methods bypass _check_approval entirely, including scroll, key_down, key_up, screenshot, copy_to_clipboard, and window activation. This creates a false sense of safety and allows impactful actions or sensitive data access to occur without the promised approval barrier.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The guide presents open-ended natural-language execution such as drawing, typing, launching apps, and autonomous adaptation without defining allowed scopes, confirmation gates, or excluded high-risk actions. In a desktop-control skill, vague triggers materially increase the chance of unintended actions, prompt abuse, or execution in the wrong application or account context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The guide states that the agent takes screenshots of results as part of autonomous execution but provides no privacy notice, retention policy, or warning that screenshots can capture sensitive information from the desktop. Because screenshots may include emails, documents, tokens, chats, or other unrelated data, automatic capture and storage creates avoidable exposure.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The guide expands a desktop automation skill into an externally connected LLM workflow that sends user task content to a remote API using an environment-sourced bearer token. That is risky because desktop automation tasks may contain sensitive on-screen, account, or file-related context, and the documentation does not define data minimization, consent, or trust boundaries for what gets transmitted off-host.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
86% confidence
Finding

This code performs an outbound POST to a remote API with task content and an authorization token. Even if intended for legitimate planning, it creates a data egress path from a desktop agent that may handle sensitive instructions or derived screen context, and the guide does not describe safeguards around what is sent.

Content

Scanner excerpt · AI_AGENT_GUIDE.md (reported line 277)May include surrounding context.

md
API_BASE = "https://api.heybossai.com/v1"

def pilot(body: dict) -> dict:
    r = requests.post(
        f"{API_BASE}/pilot",
        headers={"Authorization": f"Bearer {SKILLBOSS_API_KEY}", "Content-Type": "application/json"},
        json=body,

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The examples encourage high-impact actions such as form filling, social media posting, file operations, and copying data between applications without warning that the agent may alter user data or act in external accounts. In a desktop automation context, these actions can cause irreversible changes, data leakage, or unauthorized transactions if executed in the wrong context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The quick reference explicitly demonstrates taking screenshots and saving them to disk, which can capture sensitive on-screen data such as credentials, personal information, internal documents, or tokens. In a desktop automation skill, screen capture is a high-risk capability, and documenting it without a clear privacy warning or consent guidance increases the chance of accidental collection or retention of sensitive data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The examples show autofilling a password, copying data via clipboard, and switching windows to paste content, all of which can expose secrets or send data to the wrong application if focus changes unexpectedly. In a desktop control skill, these patterns materially increase the risk of credential leakage, clipboard exfiltration, or unintended actions unless the documentation strongly warns about handling sensitive data and validating window focus.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill exposes powerful automation capabilities and its documented installation/use implies access to environment and potentially network-retrieved dependencies, yet it declares no explicit tool scope or permissions boundary. In a desktop-control skill, missing scope declarations are dangerous because they obscure the true privilege surface and make it easier for downstream agents or users to invoke sensitive actions without informed consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill documents screen capture and saving screenshots to disk without clearly warning that screenshots may include passwords, personal messages, tokens, financial data, or other sensitive on-screen content. In a desktop automation context this is especially risky because capture can be broad, silent, and persistent once written to local files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documented clipboard read capability can expose highly sensitive transient data such as passwords, API keys, personal messages, or financial information, yet no privacy warning or access constraint is provided. In this skill, clipboard access is more dangerous because it pairs naturally with automation and exfiltration-adjacent workflows, making silent collection easier.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The screenshot method captures the full screen or a region and can save it to disk without any approval check or in-context disclosure. Screenshots may include messages, credentials, personal files, or other sensitive on-screen information, so silent capture materially increases privacy and data-exposure risk.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The implementation includes window enumeration, active-window inspection, and window activation, but these capabilities are not reflected in the description. Undisclosed window control expands the skill's ability to inspect user context and steer interaction toward sensitive applications without reviewer or user awareness.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill description advertises desktop automation but does not disclose clipboard capabilities, while the code can both write to and read from the system clipboard. Clipboard access can expose passwords, tokens, copied documents, and other sensitive data, so omitting it from the stated capability set undermines informed consent and review.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Writing arbitrary text to the clipboard can overwrite user data and manipulate downstream paste actions without consent. In a desktop automation context, this can alter user workflows, replace copied secrets, or stage misleading or harmful content for later pasting.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill can read arbitrary clipboard contents even though the declared purpose is desktop control and does not justify data collection from the clipboard. Clipboard contents often contain secrets or private user data, making silent reads a confidentiality risk and a potential exfiltration primitive.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Clipboard reads occur without approval or disclosure, allowing the skill to access potentially sensitive user data such as passwords, API keys, addresses, or confidential text. In combination with desktop automation, this becomes more dangerous because the same skill can also redirect focus, capture screens, and type or paste collected data elsewhere.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The agent automatically captures screenshots before and after each execution step and stores them in the returned result structure without any consent, minimization, or disclosure. Because screenshots can contain passwords, messages, documents, tokens, and unrelated applications, this creates a real privacy and data-retention risk in a desktop automation skill with broad screen access.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · ai_agent.py (reported line 165)May include surrounding context.

python
# Example:
        #   import requests, os
        #   SKILLBOSS_API_KEY = os.environ["SKILLBOSS_API_KEY"]
        #   r = requests.post(
        #       "https://api.heybossai.com/v1/pilot",
        #       headers={"Authorization": f"Bearer {SKILLBOSS_API_KEY}", "Content-Type": "application/json"},
        #       json={"type": "chat", "inputs": {"messages": [{"role": "user", "content": task}]}, "prefer": "balanced"},

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · AI_AGENT_GUIDE.md (reported line 274)May include surrounding context.

md
#   import requests, os
        #   SKILLBOSS_API_KEY = os.environ["SKILLBOSS_API_KEY"]
        #   r = requests.post(
        #       "https://api.heybossai.com/v1/pilot",
        #       headers={"Authorization": f"Bearer {SKILLBOSS_API_KEY}", "Content-Type": "application/json"},
        #       json={"type": "chat", "inputs": {"messages": [{"role": "user", "content": task}]}, "prefer": "balanced"},
        #       timeout=60,

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · ai_agent.py (reported line 166)May include surrounding context.

python
#   import requests, os
        #   SKILLBOSS_API_KEY = os.environ["SKILLBOSS_API_KEY"]
        #   r = requests.post(
        #       "https://api.heybossai.com/v1/pilot",
        #       headers={"Authorization": f"Bearer {SKILLBOSS_API_KEY}", "Content-Type": "application/json"},
        #       json={"type": "chat", "inputs": {"messages": [{"role": "user", "content": task}]}, "prefer": "balanced"},
        #       timeout=60,

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This step writes screenshots to disk using a caller-controlled filename without any user disclosure or retention controls. Persisting screen contents to local storage increases the chance that sensitive information remains accessible to other processes, users, backups, or forensic recovery.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.