Back to skill

Security audit

节点

Security checks for vulnerabilities and agentic risk

Overview

This skill is for macOS screen snapshots, but it uses screen recording with broad activation guidance, weak privacy disclosure, and an unsafe shell placeholder pattern.

Review before installing. Only use this skill when you intentionally want a screen snapshot of a specific node or window, close or redact sensitive content first, and ensure the runner validates node identifiers or passes them as structured command arguments. Delete the generated MP4 and PNG when no longer needed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:66
Finding

Shell Command Injection Through Unvalidated Node Identifier

Content
View full analysis
" --duration 1000 --fps 10 --no-audio --out "{skill}/tmp/snap.mp4" \ && ffmpeg -hide_banner -loglevel error -y -ss 00:00:00 -i "{skill}/tmp/snap.mp4" -frames:v 1 "{skill}/tmp/snap.png" ``` ### Technical Analysis The documented workflow places the node identifier directly into a shell command without defining validation or a safe argument-passing mechanism. If an Agent implements this workflow by replacing the `` placeholder with user-controlled text before passing the resulting string to a shell, an attacker can supply shell metacharacters that terminate the quoted argument and introduce additional commands. Double quotes alone do not make textual shell-command construction safe. An input containing a double quote followed by shell operators can escape the intended argument context. The `{skill}` placeholder presents a similar risk if it can be influenced by an untrusted party, although the document appears to treat it as runtime-controlled metadata. ### Attack Path 1. An attacker submits a crafted node identifier through the Skill invocation interface. 2. The Agent substitutes that identifier into the `` placeholder in the documented Bash command. 3. The crafted value closes the quoted `--node` argument and adds shell syntax, for example a value following the pattern `"; attacker-command; #`. 4. The Agent passes the assembled command string to a shell. 5. The shell interprets the injected content as a separate command and executes it with the Agent process's privileges. Successful exploitation depends on the runtime performing textual placeholder substitution and executing the result through a shell. ### Impact Assessment Successful exploitation can provide arbitrary command execution with t ...[truncated 720 chars]
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill description says it should be used when the user needs 'node-related functionality,' which is far broader than its actual capability of screen recording/snapshot extraction. Overly broad activation criteria can cause an agent to invoke a privacy-sensitive skill in unrelated contexts, increasing the chance of unnecessary screen capture and unintended collection of sensitive on-screen data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill performs screen recording and writes both an MP4 and PNG to disk, but it does not present a prominent upfront warning that this action may capture sensitive information visible on screen or leave privacy-sensitive artifacts in storage. In context, this is more dangerous because screen capture can collect passwords, messages, tokens, documents, or other confidential material from unrelated applications without users fully understanding the exposure.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The FAQ states '不支持,mac-node-snapshot技能仅支持截取屏幕快照', which denies video-recording capability. However, the main capability description and shell workflow show screen record --duration 1000 producing snap.mp4 before extracting a PNG frame, so the documented implementation does use video recording as an intermediate step.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The file says 'LLM API' is required and provides export API_KEY=... instructions, implying external API-based operation. Elsewhere, the actual documented workflow consists of local command execution (skill-platform nodes screen record and ffmpeg) with no API call or key usage described, so the documentation gives a contradictory picture of how the skill works.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.