Back to skill

Security audit

Desktop Control

Security checks across malware telemetry and agentic risk

Overview

This skill is for desktop automation, but it grants broad screen, keyboard, mouse, window, and clipboard control with weak scoping and safety guidance.

Install only if you intentionally want an agent to control your desktop. Keep failsafe and approval mode enabled, avoid running it with administrator privileges unless necessary, and do not use it while sensitive windows, passwords, private documents, or clipboard contents are visible.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The skill claims that risk code was removed and safety was enhanced, yet the same document advertises arbitrary mouse and keyboard control, screenshot capture, window enumeration, clipboard access, and even suggests disabling failsafe for performance. This mismatch can mislead users and reviewers into trusting a highly privileged automation skill without understanding its real capability to exfiltrate data or perform unauthorized actions on the desktop.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The trigger keywords are generic terms like 'mouse', 'automation', 'advanced', 'control', and 'desktop', which are likely to match ordinary user requests unrelated to granting broad desktop-control powers. In an agent ecosystem, this raises the chance the skill is invoked unexpectedly, exposing powerful input simulation and screen-access functions in contexts where the user did not intend that level of access.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill description highlights screenshots, window listing, and clipboard operations but does not clearly warn that these features can expose passwords, personal data, confidential documents, and session contents from other applications. In the context of a desktop-control skill, omission of privacy warnings is especially dangerous because these capabilities directly access sensitive user data beyond the immediate task.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.