Back to skill

Security audit

Omniscient

Security checks for vulnerabilities and agentic risk

Overview

This skill gives an agent broad Windows, network, camera, microphone, GUI, and smart-home control, but its scope and safety controls are too broad and inconsistent for routine installation.

Install only if you intentionally want a powerful local Windows automation and device-control skill. Review every command before execution, avoid using it with untrusted prompts or webpages, do not expose `HA_TOKEN` unless the Home Assistant URL is fixed and trusted, and treat Wi-Fi password display, camera/microphone capture, process killing, network changes, and smart-home actions as sensitive operations requiring explicit consent.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (6)

other

Error
Location
scripts/iot_controller.py:53
Finding

Environment Credential Exfiltration to Arbitrary Network Endpoints

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/network_controller.py:174
Finding

PowerShell Command Injection Through Wi-Fi SSID Parameters

Content
View full analysis
32: return "ERROR: SSID too long (max 32 chars)" err = _require_confirmation("connect_wifi") if err: return err escaped_ssid = ssid.replace("'", "''") if password: escaped_pwd = password.replace("'", "''") script = f""" try {{ # Create profile with password $xml = @" {escaped_ssid} {escaped_ssid} ESS WPA2PSKAES passPhrasefalse{escaped_pwd} "@ $profilePath = [System.IO.Path]::GetTempFileName() $xml | Out-File -FilePath $profilePath -Encoding Unicode netsh wlan add profile filename="$profilePath" 2>&1 | Out-Null Remove-Item $profilePath -Force -ErrorAction SilentlyContinue netsh wlan connect name="{escaped_ssid}" 2>&1 | ForEach-Object {{ Write-Output $_ }} ``` ```python def wifi_profile_detail(ssid): """Show details of a saved WiFi profile (including password if available).""" if not ssid or not isinstance(ssid, str): return "ERROR: SSID is required" if len(ssid) > 32: return "ERROR: SSID too long (max 32 chars)" escaped_ssid = ssid.replace("'", "''") script = f""" try {{ netsh wlan show profile name=" ...[truncated 2213 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/battery_controller.py:191
Finding

PowerShell Command Injection Through Power-Plan Name

Content
View full analysis
&1 | Where-Object {{ $_ -match '\({regex_safe}\)' }} if (-not $plan) {{ # Try partial match $plan = powercfg /list 2>&1 | Where-Object {{ $_ -match '{regex_safe}' }} }} if ($plan -and $plan -match 'GUID:\s*([0-9a-f-]+)') {{ $guid = $matches[1] powercfg /setactive $guid 2>&1 | Out-Null Write-Output "OK: Power plan switched to '{escaped}' ($guid)" }} else {{ # List available plans for guidance $available = (powercfg /list 2>&1) -join "`n" Write-Output "ERROR: Power plan '{escaped}' not found.`nAvailable plans:`n$available" }} }} catch {{ Write-Output "ERROR: $($_.Exception.Message)" }} """ stdout, _, _ = _run_ps(script, timeout=10) return stdout ``` The regex escaping function is: ```python def _escape_ps_regex(s): """Escape a string for safe use inside a PowerShell -match regex operand.""" if s is None: return None return re.sub(r'[.*+?^${}()|[\]\\]', r'\\\g<0>', s) ``` ### Technical Analysis `_escape_ps_regex()` escapes .NET regular-expression metacharacters but does not escape the surrounding PowerShell single-quoted string syntax. In particular, it leaves apostrophes and command separators unchanged. The code computes a separately escaped `escaped` variable for output messages, but embeds the unquoted-context-safe `regex_safe` value directly inside PowerShell single-quoted literals. Regex escaping and Power ...[truncated 849 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/network_controller.py:264
Finding

Saved Wi-Fi Password Disclosure Without Confirmation or Redaction

Content
View full analysis
32: return "ERROR: SSID too long (max 32 chars)" escaped_ssid = ssid.replace("'", "''") script = f""" try {{ netsh wlan show profile name="{escaped_ssid}" key=clear 2>&1 | Out-String }} catch {{ Write-Output "ERROR: $($_.Exception.Message)" }} """ stdout, _, _ = _run_ps(script) return stdout ``` ### Technical Analysis The `key=clear` option explicitly instructs Windows to display saved Wi-Fi key material in plaintext. The complete command output is returned without redaction. The operation has no confirmation gate, user-presence check, credential-specific authorization, or output filtering. Merely viewing profile details does not require disclosure of the underlying Wi-Fi password, so this behavior exceeds minimum privilege for ordinary network inspection. The same function is also affected by the SSID command-injection issue reported separately. ### Attack Path 1. An attacker or untrusted task enumerates saved Wi-Fi profiles using the Skill. 2. It invokes `wifi profile-detail` for a selected SSID. 3. The function runs `netsh wlan show profile ... key=clear`. 4. Windows includes the plaintext saved key when the current security context permits access. 5. The Skill returns the output to the Agent. 6. The credential may then be exposed through chat output, logs, tool traces, or subsequent prompts. ### Impact Assessment The disclosed password can permit unauthorized access to the victim's wireless network. Potential consequences include: - Unauthorized network access. - Access to internal services and devices ...[truncated 377 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/process_manager.py:132
Finding

Destructive Process and Window Operations Bypass Declared Confirmation Requirements

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/camera_controller.py:52
Finding

Automatic Runtime Installation of Mutable Third-Party Dependencies

Content
View full analysis
=4.9.0.80,<5", "-q"]) import cv2 return cv2 ``` Comparable automatic installation is present for `pycaw`, `sounddevice`, `psutil`, `bleak`, `pyautogui`, `pillow`, `pytesseract`, `requests`, and `pyserial`. For example: ```python subprocess.check_call( [sys.executable, "-m", "pip", "install", "requests>=2.31.0,<3", "-q"], stdout=subprocess.DEVNULL ) ``` ### Technical Analysis When an import fails, the controllers automatically invoke pip using a version range. The package source is determined by the interpreter's current pip configuration, and neither exact versions nor package hashes are enforced. Although upper and lower version bounds reduce accidental incompatibility, they do not make the dependency immutable. A future release within the accepted range, a compromised package repository, a malicious configured mirror, or a compromised transitive dependency could execute code during installation or import. Installation is performed during normal controller use, so an apparently low-risk action such as listing cameras or checking battery status can unexpectedly modify the Python environment and execute externally sourced installation artifacts. The camera pre-scan alert is not a reverse shell: the command uses a fixed list of arguments and does not establish a command-and-control connection. It is nevertheless an unsafe supply-chain operation. ### Attack Path 1. A controller is invoked in an environment where its optional package is absent. 2. The import raises `ImportError ...[truncated 982 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (83)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

There is a strong description-behavior mismatch. The declared description presents a sweeping, universal, multi-layer skill with orchestration and broad system-control capabilities across numerous device classes and task types. The supplied code, however, is limited to audio management on Windows: enumerating sound devices, changing default audio endpoints, controlling volume, and recording microphone input. While audio devices are one subset mentioned in the description, the actual code does not implement the vast majority of the declared capabilities, nor any general-purpose orchestration or cognition framework. This is not merely over-declaration of permissions; the primary purpose described is materially broader and different from the code’s actual narrow behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description vastly overstates the skill's functionality. The supplied code only implements battery and Windows power-management operations: querying battery information, listing/getting/setting power plans, and generating a battery report. It does not provide a general orchestration engine, arbitrary code generation/execution framework, broad software/hardware control, or universal task applicability. While battery/power control is one small subset of the declared system-control layer, the actual code is materially narrower than the description, so the description does not accurately represent the code's real behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

There is a clear description-behavior mismatch. The description claims an extremely broad, unified, all-capable system spanning cognition, execution, orchestration, and control of many classes of software and hardware. The actual code chunk only implements Bluetooth-related device management functions. While Bluetooth control is one small subset of the declared scope, the declared primary purpose is materially broader and presented as universally applicable without exception. The code does not contain the claimed orchestration engine, general execution framework, or the many other device/system control domains listed. This is not merely over-declared permission; it is a materially inaccurate representation of the code's real behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The supplied code does not implement a general-purpose omnipotent skill. It only provides camera-specific functionality: enumerating cameras via WMI/OpenCV, inspecting camera properties, and capturing a still image. Although it uses subprocess/pip installation and PowerShell for support tasks, these are implementation details in service of camera management, not evidence of the declared broad execution framework or universal orchestration engine. The description materially overstates the scope and primary purpose, claiming sweeping device/system control and applicability to any task, while the actual code is limited to webcam access and image capture on Windows.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

There is a clear description-behavior mismatch. The declared purpose advertises a massive multi-layer capability suite with reasoning modes, execution framework, orchestration, and direct control over numerous hardware/software domains. The supplied code does not implement those capabilities. It only exposes helper functions to run PowerShell and guarded shell commands plus a tiny serialization helper. While command execution could be a supporting building block for a larger system controller, this chunk by itself does not demonstrate the claimed orchestration engine, broad device-control interfaces, cognition layer, or universal applicability. This is not merely incomplete detail; the actual code's primary purpose is much narrower than the declared description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The description vastly overstates the skill's purpose and scope. The code chunk only implements monitor/display-related operations on Windows: querying display info, multi-monitor layout, DPI, Night Light, and orientation. There is no evidence in this code of a general cognition suite, LLM-based automation, arbitrary command execution, orchestration across primitive actions, or control of the many other listed hardware/software domains. While 'display/monitor' control is one small subset of the declared description, the declared primary purpose is materially different and much broader than the actual behavior shown. Therefore this is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The description massively overstates the skill's scope. The actual code implements a specific GPU utility for Windows focused on NVIDIA GPUs and nvidia-smi. It can monitor GPU state and adjust GPU power limits, but it does not implement the broad multi-layer cognitive/execution/orchestration platform described. There is no evidence of LLM integration, arbitrary command execution exposed as a feature, desktop app automation, system-wide hardware control across the listed device categories, or universal task applicability. While GPU control is one small subset of the declared hardware-control claims, the primary purpose and actual resource access are materially narrower than declared, so this is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

该描述与代码行为存在明显不匹配。代码内容聚焦于桌面 GUI 自动化:通过 pyautogui 执行鼠标/键盘输入、截图、OCR、图像定位与点击、颜色检测,并借助 PowerShell 获取前台窗口坐标或提供 OCR 回退信息。这确实涉及一小部分“Windows桌面软件/图形界面自动化”能力,但远不足以支撑声明中的广泛能力版图。声明将技能描述为通用认知+执行+系统/硬件全控制+编排引擎的“全知全能”套件,而实际代码没有任何认知推理模块、LLM 集成、任意命令执行接口、硬件设备管理接口或复杂编排框架。根据评估标准,这是对主要用途和能力范围的重大夸大,属于描述与实际行为不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

There is a strong description-behavior mismatch. The declared purpose presents a sweeping, universal capability stack spanning cognition, execution, system control, and orchestration across many hardware and software domains. The supplied code does not implement anything close to that breadth. Instead, it is a single-purpose Windows hardware control utility with a constrained CLI and a limited set of actions: audio volume/mute, brightness, display info, power operations, and USB listing. While some of these actions partially overlap the broad 'system/hardware control' claims, the vast majority of declared capabilities are absent, including LLM-based automation, general orchestration, GUI automation, Bluetooth, serial, IoT, storage, printers, cameras, fan/temperature control, and broad arbitrary-task execution. The primary purpose of the code is materially narrower than the description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The description dramatically overstates the skill's purpose relative to the code provided. The code only enumerates input devices on Windows: keyboards, mice, and gamepads. It does not control devices, execute arbitrary automation chains, provide a cognition layer, manage software, or interact with the many hardware/resource categories claimed in the description. While over-declared permissions alone should not trigger a mismatch, this is not merely overbroad wording—the declared primary purpose is materially different from the actual behavior. Therefore this is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

该描述与代码行为存在明显且重大的不一致。描述宣称这是一个几乎无所不能的综合技能,涵盖认知、代码生成执行、系统级控制和广泛硬件/外设操控,并具有通用编排能力;但代码只是单一用途的 IoT 控制 CLI,核心功能是向 Home Assistant 或任意 HTTP 端点发送请求,以及输出 Mijia 发现说明。虽然“物联网平台控制”这一小部分与声明有局部重合,但其余绝大多数关键能力均未在代码中出现,且代码的主要目的与“全知全能、适用于任何任务”的定位严重不符,因此应判定为描述夸大且失实的能力声明。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The supplied code does not implement a general-purpose omnipotent skill. It specifically manages Windows networking: listing/enabling/disabling adapters, scanning/connecting/disconnecting WiFi, showing WiFi profiles (including cleartext key display), reading and setting DNS, reading and setting proxy settings, and ping tests. While these actions fit a small subset of the declared 'system control' theme, the description materially overstates the implemented scope and primary purpose. There is no evidence here of cognition modules, broad command-execution automation, arbitrary task orchestration, or control of the many other claimed device/resource categories. Therefore the description does not accurately represent the actual behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description vastly overstates the skill's scope and purpose. The supplied code implements only printer-related operations on Windows via built-in PowerShell/CIM interfaces: enumerating printers, reading/changing the default printer, listing and cancelling print jobs, and retrieving printer capabilities. It does not provide a general orchestration engine, reasoning framework, code generation/execution framework, or broad system/hardware control across the many resource types listed. While printer control is one small subset mentioned in the description, the declared purpose says the skill can handle essentially any task with integrated cognition, execution, and system control, which is materially inaccurate for this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

该描述与代码行为明显不符。代码的核心用途是本地 Windows 进程管理与少量系统状态查询,而描述宣称的是一个覆盖几乎所有任务和多种系统/硬件控制面的通用“全知全能”技能。虽然代码确实涉及部分系统控制(启动/终止进程、查看资源),与描述中的“系统控制”大类存在很弱的重叠,但远不足以支撑其所宣称的广泛能力范围。未发现代码实现认知层思维操作码、编排引擎、GUI 自动化、硬件外设控制、物联网/蓝牙/GPU/磁盘/电源等关键能力,因此应判定为描述与实际行为存在重大不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

There is a clear description-behavior mismatch. The declared purpose presents a sweeping, all-capable platform covering reasoning modes, automation, orchestration, and control of many categories of software and hardware. The supplied code does only three scanner-related tasks on Windows: list scanner devices via WIA/WSD/PnP, show WIA device information, and report WIA service availability. While the code does access a limited hardware-related area (scanner/image devices) using PowerShell and Windows services/registry/PnP, that is only a tiny subset of the declared functionality. The primary purpose is scanner enumeration and status inspection, not a universal execution/control engine.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The supplied code does not implement the vast majority of the declared capabilities. Its real purpose is limited to serial device communication via pyserial, with a small CLI exposing list/detect/send/receive/chat/monitor operations. While serial-device interaction is one small subset of the declared hardware/control claims, the description presents a general-purpose omnipotent execution and orchestration suite applicable to any task, which is materially inaccurate for this code chunk. The only notable extra behavior is automatic installation of pyserial via pip, which is a supporting implementation detail rather than the primary mismatch. Therefore the description substantially overstates and misrepresents the code's actual behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

There is a clear description-behavior mismatch. The declaration presents an extremely broad, omnipotent multi-layer skill covering reasoning, execution, orchestration, and control of many system and hardware domains. The actual code chunk implements only storage-related read/analysis operations on Windows: drive listing, drive info, health/status queries, large-file search, folder usage analysis, and partition enumeration. It does not implement the vast majority of the declared capabilities, nor does it support arbitrary tasks. While the code does interact with one declared domain (storage disks), the declared purpose materially overstates the skill’s scope and primary function.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

There is a clear description-behavior mismatch. The description advertises a comprehensive omnipotent skill with broad cross-domain control and orchestration capabilities, while the actual code is limited to thermal status inspection and monitoring on Windows. The code gathers telemetry via psutil, WMI/CIM, and nvidia-smi, and returns JSON for status, CPU info, fan info, and sampled monitoring data. It does not implement the vast majority of the declared capabilities, especially arbitrary task execution, GUI/device control, IoT/Bluetooth/serial integrations, or generalized orchestration. Although thermal/fan monitoring is one small subset of the declared hardware scope, the declared purpose materially overstates the implemented behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

该描述与代码行为明显不符。代码块的主用途是 Windows 桌面窗口控制,而非一个覆盖所有任务的“全知全能”技能。虽然声明中提到“Windows桌面软件/图形界面自动化”,这与代码的部分能力有交集,但代码只提供非常具体且有限的窗口管理与发送按键功能,没有实现声明中绝大多数能力层:没有认知套件、没有 LLM 驱动的代码生成或通用脚本执行、没有硬件/IoT/蓝牙/GPU/磁盘等控制、也没有编排引擎。因此这是对能力范围和主要用途的重大夸大,属于显著不匹配。

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill prominently advertises sensitive system-control abilities—hardware, desktop software, network, Bluetooth, storage, audio, display, printers, cameras, and IoT—without equally prominent privacy and safety warnings at the point of description. In context, this is dangerous because the skill is framed as universally applicable, encouraging broad use of surveillance-capable and system-impacting functions without informed consent boundaries.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill declares an extremely broad activation scope—'applies to any task, without exception'—for a capability set that includes code execution, shell commands, file/network access, GUI automation, device control, and IoT actions. Such unconstrained triggering significantly raises the risk of the agent invoking powerful operations in inappropriate contexts, including privacy-sensitive or destructive tasks, with insufficient narrowing or human review.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 232)May include surrounding context.

md
| 级别 | 示例 | 处理方式 |
|------|------|----------|
| 🔴 高危 | `rm -rf /`、`format C:` | **必须用户确认** |
| 🟡 中危 | `pip uninstall`、`sudo` | 警告提示 |
| 🟢 低危 | `ls`、`cat`、`python script.py` | 直接执行 |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 232)May include surrounding context.

md
| 级别 | 示例 | 处理方式 |
|------|------|----------|
| 🔴 高危 | `rm -rf /`、`format C:` | **必须用户确认** |
| 🟡 中危 | `pip uninstall`、`sudo` | 警告提示 |
| 🟢 低危 | `ls`、`cat`、`python script.py` | 直接执行 |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
96% confidence
Finding

This is a true tool-parameter abuse risk because the wrapper exposes shell execution as a reusable primitive and relies on weak filtering instead of safe process invocation. Within a powerful orchestration skill that can operate across system components, a generic shell-capable helper materially increases the blast radius of any upstream validation mistake.

Content

Scanner excerpt · scripts/bluetooth_controller.py (reported line 61)May include surrounding context.

python
return "", f"ERROR: Command blocked - contains '{blocked}'", -1

    try:
        result = subprocess.run(
            cmd, shell=True, capture_output=True, text=True,
            encoding="utf-8", errors="replace", timeout=timeout
        )

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · scripts/common.py (reported line 33)May include surrounding context.

python
Returns:
        Tuple of (stdout: str, stderr: str, returncode: int)
    """
    env = os.environ.copy()
    env["PYTHONIOENCODING"] = "utf-8"

    # Prepend encoding setup to ensure UTF-8 output

Static analysis

No suspicious patterns detected.