Back to skill

Security audit

TuriX Computer Use

Security checks across malware telemetry and agentic risk

Overview

This skill appears legitimate, but it gives an AI broad control over a Mac desktop and does not sufficiently scope or warn about sensitive account, file, and permission risks.

Install only if you intentionally want an AI agent to see and control your Mac desktop. Use a reviewed or pinned TuriX-CUA checkout, supervise runs, avoid personal or production accounts, require confirmation before uploads, submissions, sending files, account changes, purchases, or deletions, and revoke Screen Recording and Accessibility permissions when finished.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Lp3

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding
The skill exposes capabilities to read environment variables and read/write files, but the frontmatter declares no permissions or trust boundaries. For a desktop automation skill, that omission is dangerous because operators may invoke it without realizing it can access local data, modify files, and persist artifacts like logs or generated documents.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The README explicitly suggests an automated GUI workflow to 'sign up with Google account' without any warning about handling credentials, MFA prompts, consent screens, or other sensitive account data. In a desktop-control skill, this normalizes using the agent for identity-linked actions and could lead users to expose passwords, tokens, or personal data to the automation stack or to unintended UI interactions.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill is described as visually controlling the macOS desktop and performing complex workflows autonomously, but it does not clearly warn that this can expose emails, documents, browser sessions, credentials, or actions on third-party services. In this context, omission of that warning increases the risk of unsafe use because the agent operates over highly sensitive UI surfaces with broad implicit authority.

Missing User Warnings

Medium
Confidence
85% confidence
Finding
The examples explicitly instruct creation of folders and elsewhere discuss sending or uploading files, but they do not pair those actions with warnings about modifying user data or transferring sensitive content. Because this is a GUI automation skill, those operations may affect real user files and external systems, making accidental data loss or exfiltration more plausible.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The troubleshooting section recommends granting screen recording and accessibility-like permissions, including running an AppleScript snippet, without explaining the security implications of those privileges. These permissions allow broad observation and control of the desktop, so normalizing their use without warnings can lead users to over-grant access and materially increase the blast radius of misuse or compromise.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.