Back to skill

Security audit

Desktop Automation Pro

Security checks for vulnerabilities and agentic risk

Overview

The skill is transparently a GUI automation guide, but it gives broad desktop and paired-device control guidance without enough scoping or consent guardrails.

Install only if you intentionally want broad automation over browsers, the active desktop, Windows apps, and paired devices. Before using it, confirm every camera, screen-recording, location, screenshot, global input, and remote-command action, keep sensitive windows closed, avoid administrator sessions unless strictly necessary, and use pinned dependencies in an isolated virtual environment.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:153
Finding

Unpinned Third-Party Dependencies Permit Unreviewed Supply-Chain Changes

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:153, scripts/pyautogui_demo.py:10, and scripts/pywinauto_demo.py:9
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Relevant code snippets:

SKILL.md:153

bash
pip install pyautogui pywinauto pillow

scripts/pyautogui_demo.py:10

text
pip install pyautogui pillow

scripts/pywinauto_demo.py:9

text
pip install pywinauto

Technical Analysis

The documented installation commands install mutable versions of pyautogui, pywinauto, and pillow from pip. The project does not provide reviewed version constraints, package hashes, or a dependency lockfile. Transitive dependencies are similarly unconstrained.

Consequently, the code installed by users can differ from the dependency versions assessed during this audit. If a future package release or one of its transitive dependencies is compromised, unexpectedly modified, or removed and replaced, installation or import-time code could execute with the privileges of the user running pip or the demonstration scripts.

No evidence was found that the currently named packages are malicious. The issue is the absence of controls ensuring that users receive known, reviewed package artifacts.

Attack Path

  1. A user follows the installation instructions supplied by the project.
  2. pip queries its configured package index and resolves the latest compatible package releases and transitive dependencies.
  3. A compromised, malicious, or unexpectedly changed package release is selected because no reviewed version or artifact hash is enforced.
  4. Package installation logic executes during installation, or package code executes when the scripts import pyautogui or pywinauto.
  5. The dependency gains access to the files, environment variables, desktop session, and other resources available to the invoking user.

Impact Assessment

Successful exploitation wo ...[truncated 588 chars]

Remediation
View remediation

Remediation Suggestions

  1. Create a reviewed dependency file that pins every direct and transitive dependency to an exact version.
  2. Generate and record cryptographic hashes for all approved distribution artifacts.
  3. Install dependencies using hash verification, for example:
    bash
    python -m pip install --require-hashes -r requirements.txt
    
  4. Use a lockfile-producing dependency-management tool and commit the lockfile to the project.
  5. Document the trusted package index explicitly and prohibit unreviewed extra indexes or package mirrors.
  6. Run dependency vulnerability and provenance checks whenever pinned versions are updated.
  7. Install and execute the automation scripts in an isolated virtual environment under a non-administrative account.
  8. Replace the existing unconstrained installation examples in SKILL.md and both script docstrings with the verified requirements-file command.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The supplied code only demonstrates local desktop GUI automation using PyAutoGUI: mouse movement/clicking, keyboard typing/hotkeys, and screenshots. These behaviors do align with part of the description, especially mouse/keyboard simulation and screenshot capture. However, the declared purpose substantially overstates the implemented scope by claiming browser automation, paired mobile device control, and native Windows application automation, none of which are present in this code chunk. Therefore the description does not accurately represent what this specific code actually does.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill advertises camera access, screen recording, and location retrieval without any privacy warning or consent guidance. These capabilities can capture highly sensitive personal or enterprise data from paired devices, and the absence of warnings increases the risk of misuse or accidental over-collection.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Documenting nodes action=run for paired iOS/macOS devices exposes arbitrary command execution on external devices, which goes beyond narrowly scoped GUI automation. If invoked without strict authorization and guardrails, it could be used to execute harmful commands, access sensitive data, or alter device state on paired endpoints.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Global mouse/keyboard simulation and execution of Python automation scripts can affect the entire host system, including unintended windows, dialogs, or privileged applications. Without a clear warning about system-wide impact, users may trigger destructive or privacy-invasive actions accidentally, and attackers could leverage the broad control surface for harmful automation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Instructing users to use exec to run Python scripts introduces open-ended code execution under the banner of GUI automation. That broad capability can be repurposed for arbitrary local actions such as file access, process spawning, credential theft, or persistence, especially because the examples interact with the host desktop environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

Screenshot guidance omits any warning that captures may include passwords, personal data, tokens, internal documents, or other sensitive on-screen content. While screenshotting is within the declared purpose of the skill, the lack of privacy caution increases the chance of accidental disclosure or inappropriate collection.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code includes bilingual Chinese/English strings in the module description and later defaults to Chinese text input, which imposes a specific locale/language behavior without explicit user opt-in. Under the stated policy, language constraints should either be optional or clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.