Back to skill

Security audit

Rebind Computer Use

Security checks across malware telemetry and agentic risk

Overview

This skill openly enables powerful real-computer control, but its scripting tool goes beyond GUI operation into broad local file, process, network, clipboard, environment, and registry access.

Install only if you trust the Rebind app and MCP package and are comfortable giving an agent practical control of your desktop. Keep the Rebind relay off when not actively using it, avoid using it around sensitive accounts unless necessary, and treat run_lua as elevated local access because it can do more than click and type.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The documented `run_lua` primitive exposes far more than keyboard/mouse control: it includes file, process, environment, clipboard, and network access, enabling arbitrary local system interaction and data exfiltration. In a skill framed as "computer use," this materially expands authority beyond the stated purpose and could let an agent bypass GUI-only constraints, read sensitive data, or execute commands without user visibility.

Unrestricted Tool Access

Medium
Category
Excessive Agency
Content
- **Skill:** `rebind-computer-use/SKILL.md` — teaches the agent when and how to
  drive the tools.
- **Tools:** the [`@rebind.gg/mcp-server`](https://www.npmjs.com/package/@rebind.gg/mcp-server)
  MCP server — `screenshot`, `zoom`, verified `click`, `type`, `key`, `scroll`,
  window control, `calibrate`.
Confidence
93% confidence
Finding
Tools:*

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.