Back to skill

Security audit

Linux Omniscient

Security checks for vulnerabilities and agentic risk

Overview

This skill openly aims to control a Linux desktop and connected devices very broadly, but its safeguards are not reliably implemented or scoped.

Review before installing. Only use this skill in a contained environment where broad desktop, device, network, and IoT control is acceptable. Do not pass real tokens or Wi-Fi passwords on command lines, avoid using it for camera/audio/serial/IoT/power actions unless you can supervise them, and prefer a narrower skill with enforced confirmations for destructive operations.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (9)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/iot_controller.py:21
Finding

Bearer Token Transmission to an Unrestricted and Potentially Unencrypted Endpoint

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/iot_controller.py:5
Finding

Arbitrary HTTP Requests Enable Server-Side Request Forgery and Internal Service Access

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/iot_controller.py:47
Finding

API Tokens and Wi-Fi Passwords Are Accepted Through Process Arguments

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/process_manager.py:27
Finding

Process Termination Bypasses Documented Confirmation and Query-First Safeguards

Content
View full analysis
`, optionally with `--force`. 3. The script immediately sends `SIGTERM` or `SIGKILL`. 4. The target process exits without an enforced confirmation step. 5. Unsaved work or service availability is lost. ### Impact Assessment The script can terminate any process that the executing OS account is permitted to signal. If the Skill runs with ele ...[truncated 176 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/serial_comm.py:23
Finding

Serial Device Commands Are Transmitted Without Device Approval or Confirmation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/camera_controller.py:40
Finding

User-Controlled Output Paths Permit Arbitrary Writable-File Replacement

Content
View full analysis
text
{stdout}
') ``` ### Technical Analysis The scripts accept caller-selected output paths without canonicalization, directory containment checks, symlink rejection, exclusive creation, or overwrite confirmation. Camera capture and battery report generation can therefore replace existing files writable by the process. Audio recording has the same unsafe path design, although it currently fails before execution because `run_cmd()` rejects the list argument. ### Attack Path 1. An attacker selects an existing user-writable file or creates a sym ...[truncated 635 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/common.py:87
Finding

Shell Execution Helper Uses an Incomplete Denylist with shell=True

Content
View full analysis
10000: return "", "ERROR: Command exceeds maximum length of 10000 characters", -1 dangerous_chars = ['`$', '$(', '${', '`', ';', '&&', '||'] cmd_str = command.strip() for char in dangerous_chars: if char in cmd_str: return "", f"ERROR: Command blocked - contains '{char}' (use list-based invocation)", -1 env = os.environ.copy() env["PYTHONIOENCODING"] = "utf-8" try: result = subprocess.run( cmd_str, capture_output=True, text=True, encoding="utf-8", errors="replace", timeout=timeout, shell=True, env=env ) ``` ### Technical Analysis The helper sends a string to the operating-system shell and attempts to prevent injection with a denylist. The list is incomplete: it does not reject newline separators, pipes, redirections, or a single background operator. Shell parsing is too complex to secure through selective character blocking. There is also a contradictory API defect: nearly all controllers pass argument lists, while the helper rejects every non-string input. This currently makes most advertised controller operations nonfunctional. It does not make the helper safe; any current or future string caller remains exposed to shell interpretation. ### Attack Path 1. A caller constructs a string command containing attacker-controlled input. 2. The input uses shell syntax not covered by the denylist, such as a newline, pipe, or redirection. 3. `run_cmd()` accepts the string. 4. `sub ...[truncated 683 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/hardware_controller.py:51
Finding

Power and Network Reconfiguration Commands Lack Implemented Confirmation Gates

Content
View full analysis
0: stdout, _, code = run_cmd(['shutdown', '-h', f'+{delay//60}']) else: stdout, _, code = run_cmd(['shutdown', '-h', 'now']) return json.dumps({"success": code == 0, "message": stdout}, indent=2) def restart_system(delay=0): """Restart system.""" if delay > 0: stdout, _, code = run_cmd(['shutdown', '-r', f'+{delay//60}']) else: stdout, _, code = run_cmd(['shutdown', '-r', 'now']) return json.dumps({"success": code == 0, "message": stdout}, indent=2) ``` ```python def disable_adapter(name): """Disable network adapter (requires confirmation).""" stdout, _, code = run_cmd(['ip', 'link', 'set', name, 'down']) return json.dumps({"success": code == 0, "message": stdout}, indent=2) def set_dns(adapter, servers): """Set DNS for adapter.""" server_list = servers.split(',') stdout, _, code = run_cmd(['nmcli', 'connection', 'modify', adapter, 'ipv4.dns', servers]) return json.dumps({"success": code == 0, "message": stdout}, indent=2) ``` ### Technical Analysis The Skill documentation says shutdown, restart, sleep, hibernation, process termination, and network-adapter disabling require confirmation. No confirmation mechanism exists in these implementations. These particular operations currently fail because ...[truncated 894 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:8
Finding

Dependencies Are Installed Without Reproducible Version and Integrity Controls

Content
View full analysis
=5.9.0 - pycaw>=2023.3 - comtypes>=1.2.0 - sounddevice>=0.4.6 - pyautogui>=0.9.54 - pytesseract>=0.3.10 - Pillow>=10.0.0 - pyserial>=3.5 - requests>=2.31.0 - bleak>=0.21.0 - opencv-python>=4.8.0 - numpy>=1.24.0 system: - apt-get update && apt-get install -y x11-utils wmctrl xdotool alsa-utils pulseaudio-utils lm-sensors upower sane-utils ``` ```sh python3 -m venv ~/.venv/omniscient ~/.venv/omniscient/bin/pip install psutil pyautogui pillow pyserial requests bleak sounddevice opencv-python pytesseract ``` ### Technical Analysis The dependencies use only minimum versions or no version constraints. No lockfile, hash verification, upper bound, or trusted-index policy is provided. Installation can therefore resolve to mutable future releases that were not part of the audited artifact. The package names observed during the audit are conventional; no typosquatting or known malicious package was established. The risk arises from non-reproducible installation and unnecessarily broad dependency scope. ### Attack Path 1. The Skill creates a new environment and resolves dependencies at a later date. 2. The package index supplies a newer, compromised, or incompatible release satisfying the loose constraint. 3. Installation or import executes package-controlled code. 4. That code obtains the same filesystem and network privileges as the Skill installation or runtime process. ### Impact Assessment A compromised dependency can execute code in the Skill environment, access data available to the process, and interact with the network and hardware permissions granted to the Skill. System package installation also broadens the host attack surface. ]]>
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (67)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The description claims all-powerful control across Linux desktop software, hardware, and peripherals for any task, while the cited implementation evidence is far narrower. In context, that mismatch is dangerous because the skill already discusses screenshotting, camera, microphone, network, and command execution—areas where over-trust can directly become privacy or integrity harm.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The description claims all-powerful control across Linux desktop software, hardware, and peripherals for any task, while the cited implementation evidence is far narrower. In context, that mismatch is dangerous because the skill already discusses screenshotting, camera, microphone, network, and command execution—areas where over-trust can directly become privacy or integrity harm.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The description claims all-powerful control across Linux desktop software, hardware, and peripherals for any task, while the cited implementation evidence is far narrower. In context, that mismatch is dangerous because the skill already discusses screenshotting, camera, microphone, network, and command execution—areas where over-trust can directly become privacy or integrity harm.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The description claims all-powerful control across Linux desktop software, hardware, and peripherals for any task, while the cited implementation evidence is far narrower. In context, that mismatch is dangerous because the skill already discusses screenshotting, camera, microphone, network, and command execution—areas where over-trust can directly become privacy or integrity harm.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The description claims all-powerful control across Linux desktop software, hardware, and peripherals for any task, while the cited implementation evidence is far narrower. In context, that mismatch is dangerous because the skill already discusses screenshotting, camera, microphone, network, and command execution—areas where over-trust can directly become privacy or integrity harm.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The description claims all-powerful control across Linux desktop software, hardware, and peripherals for any task, while the cited implementation evidence is far narrower. In context, that mismatch is dangerous because the skill already discusses screenshotting, camera, microphone, network, and command execution—areas where over-trust can directly become privacy or integrity harm.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The description claims all-powerful control across Linux desktop software, hardware, and peripherals for any task, while the cited implementation evidence is far narrower. In context, that mismatch is dangerous because the skill already discusses screenshotting, camera, microphone, network, and command execution—areas where over-trust can directly become privacy or integrity harm.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The description claims all-powerful control across Linux desktop software, hardware, and peripherals for any task, while the cited implementation evidence is far narrower. In context, that mismatch is dangerous because the skill already discusses screenshotting, camera, microphone, network, and command execution—areas where over-trust can directly become privacy or integrity harm.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The description claims all-powerful control across Linux desktop software, hardware, and peripherals for any task, while the cited implementation evidence is far narrower. In context, that mismatch is dangerous because the skill already discusses screenshotting, camera, microphone, network, and command execution—areas where over-trust can directly become privacy or integrity harm.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The description claims all-powerful control across Linux desktop software, hardware, and peripherals for any task, while the cited implementation evidence is far narrower. In context, that mismatch is dangerous because the skill already discusses screenshotting, camera, microphone, network, and command execution—areas where over-trust can directly become privacy or integrity harm.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The description claims all-powerful control across Linux desktop software, hardware, and peripherals for any task, while the cited implementation evidence is far narrower. In context, that mismatch is dangerous because the skill already discusses screenshotting, camera, microphone, network, and command execution—areas where over-trust can directly become privacy or integrity harm.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The description claims all-powerful control across Linux desktop software, hardware, and peripherals for any task, while the cited implementation evidence is far narrower. In context, that mismatch is dangerous because the skill already discusses screenshotting, camera, microphone, network, and command execution—areas where over-trust can directly become privacy or integrity harm.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The description claims all-powerful control across Linux desktop software, hardware, and peripherals for any task, while the cited implementation evidence is far narrower. In context, that mismatch is dangerous because the skill already discusses screenshotting, camera, microphone, network, and command execution—areas where over-trust can directly become privacy or integrity harm.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The description claims all-powerful control across Linux desktop software, hardware, and peripherals for any task, while the cited implementation evidence is far narrower. In context, that mismatch is dangerous because the skill already discusses screenshotting, camera, microphone, network, and command execution—areas where over-trust can directly become privacy or integrity harm.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The description claims all-powerful control across Linux desktop software, hardware, and peripherals for any task, while the cited implementation evidence is far narrower. In context, that mismatch is dangerous because the skill already discusses screenshotting, camera, microphone, network, and command execution—areas where over-trust can directly become privacy or integrity harm.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The description claims all-powerful control across Linux desktop software, hardware, and peripherals for any task, while the cited implementation evidence is far narrower. In context, that mismatch is dangerous because the skill already discusses screenshotting, camera, microphone, network, and command execution—areas where over-trust can directly become privacy or integrity harm.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The description claims all-powerful control across Linux desktop software, hardware, and peripherals for any task, while the cited implementation evidence is far narrower. In context, that mismatch is dangerous because the skill already discusses screenshotting, camera, microphone, network, and command execution—areas where over-trust can directly become privacy or integrity harm.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The description claims all-powerful control across Linux desktop software, hardware, and peripherals for any task, while the cited implementation evidence is far narrower. In context, that mismatch is dangerous because the skill already discusses screenshotting, camera, microphone, network, and command execution—areas where over-trust can directly become privacy or integrity harm.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The description claims all-powerful control across Linux desktop software, hardware, and peripherals for any task, while the cited implementation evidence is far narrower. In context, that mismatch is dangerous because the skill already discusses screenshotting, camera, microphone, network, and command execution—areas where over-trust can directly become privacy or integrity harm.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill prominently advertises powerful system-control and device-access features but does not place clear privacy and system-impact warnings up front. Because it covers hardware, GUI, network, storage, Bluetooth, IoT, and other sensitive domains, users may not appreciate that loading or invoking the skill can expose secrets, alter system state, or affect connected devices.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The phrase indicating the skill applies to any task 'without exception' creates an activation scope broad enough to match essentially all user requests. For a skill that advertises command execution, orchestration, system control, and access to devices, this dramatically increases the chance of accidental or unsafe invocation in sensitive contexts.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 248)May include surrounding context.

md
| 级别 | 示例 | 处理方式 |
|------|------|----------|
| 🔴 高危 | `rm -rf /`、`format C:` | **必须用户确认** |
| 🟡 中危 | `pip uninstall`、`sudo` | 警告提示 |
| 🟢 低危 | `ls`、`cat`、`python script.py` | 直接执行 |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 248)May include surrounding context.

md
| 级别 | 示例 | 处理方式 |
|------|------|----------|
| 🔴 高危 | `rm -rf /`、`format C:` | **必须用户确认** |
| 🟡 中危 | `pip uninstall`、`sudo` | 警告提示 |
| 🟢 低危 | `ls`、`cat`、`python script.py` | 直接执行 |

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · scripts/common.py (reported line 45)May include surrounding context.

python
Returns:
        Tuple of (stdout: str, stderr: str, returncode: int)
    """
    env = os.environ.copy()
    env["PYTHONIOENCODING"] = "utf-8"

    # Prepend encoding setup to ensure UTF-8 output

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · scripts/common.py (reported line 122)May include surrounding context.

python
Returns:
        Tuple of (stdout: str, stderr: str, returncode: int)
    """
    env = os.environ.copy()
    env["PYTHONIOENCODING"] = "utf-8"

    # Prepend encoding setup to ensure UTF-8 output

Static analysis

No suspicious patterns detected.