Back to skill

Security audit

Peekaboo

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed macOS UI-automation skill for Peekaboo, with powerful but purpose-aligned capabilities and no hidden payload in the skill artifacts.

Install only if you intentionally want an agent to control your Mac UI. Grant Screen Recording and Accessibility permissions carefully, avoid using it around secrets or sensitive screens, and require explicit confirmation before actions that submit forms, enter credentials, change files, or close/quit apps.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill exposes broad macOS UI automation capabilities including clicking, typing, app control, screenshot capture, clipboard access, and dialog/menu interaction, but it does not prominently warn that these features can modify user data, trigger unintended actions, or capture sensitive on-screen information. In an agent context, omission of such warnings increases the chance of unsafe use because the documented commands are powerful enough to act on arbitrary applications and private content once Accessibility and Screen Recording permissions are granted.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The examples normalize sensitive behaviors such as entering a password-like value ("supersecret") and the feature list explicitly includes clipboard read/write, yet no warning explains that these operations may expose credentials or other sensitive data. In practice, this can encourage agents or users to automate login flows or inspect clipboard contents without appropriate safeguards, especially given the tool's ability to drive arbitrary applications.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.