Back to skill

Security audit

System Controller

Security checks for vulnerabilities and agentic risk

Overview

This skill is not clearly malicious, but it grants broad control over a Windows desktop, devices, network, screenshots, and smart-home APIs with weak implementation safeguards.

Install only if you intentionally want an agent to control your Windows desktop and connected devices. Use a dedicated, least-privileged environment, require explicit confirmation before state-changing actions, avoid passing long-lived tokens on command lines or over HTTP, and treat saved screenshots/OCR files as potentially sensitive.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (6)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/process_manager.py:99
Finding

PowerShell Command Injection in Process Startup

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/window_manager.py:270
Finding

PowerShell Command Injection Through Window Text and Title Arguments

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/hardware_controller.py:240
Finding

PowerShell Expression Injection Through Network Adapter Names

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/iot_controller.py:46
Finding

Home Assistant Tokens Exposed in Command Lines and Permitted Over Plaintext HTTP

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/iot_controller.py:27
Finding

Unpinned Runtime Installation of Third-Party Packages

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/gui_controller.py:297
Finding

Sensitive OCR Screenshot Stored in a Predictable Temporary File

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (39)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The description substantially overstates the skill’s scope. The supplied code is narrowly focused on GUI automation and screen-based interaction: moving/clicking/dragging the mouse, typing/pressing keys, taking screenshots, OCR, finding images, clicking images, and reading pixel colors. Those parts do match the description. However, the declared purpose also claims broad control over Windows software, hardware, and IoT devices, including process management, system volume/brightness, power actions, network adapters, serial/Arduino communication, USB devices, and smart home platforms. None of those capabilities are present in this code chunk. Because the declared description presents these as core supported uses rather than optional adjacent features, it does not accurately represent what this code actually does.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger scope is extremely broad, covering essentially any request about controlling software, hardware, or external devices. In a skill that can perform process management, GUI automation, power operations, networking, screenshots/OCR, and IoT/API calls, overbroad routing can cause accidental invocation on ambiguous everyday requests and lead to unintended high-impact actions.

Content

No source excerpt is available for this finding.

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · SKILL.md (reported line 88)May include surrounding context.

md
4. **Never disable critical network adapters** (the one used for active internet connection) without warning.

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · scripts/common.py (reported line 17)May include surrounding context.

python
Execute PowerShell script with proper encoding handling.
    Returns (stdout: str, stderr: str, returncode: int)
    """
    env = os.environ.copy()
    env["PYTHONIOENCODING"] = "utf-8"
    
    # Prepend encoding setup to ensure UTF-8 output

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · scripts/common.py (reported line 52)May include surrounding context.

python
Execute PowerShell script with proper encoding handling.
    Returns (stdout: str, stderr: str, returncode: int)
    """
    env = os.environ.copy()
    env["PYTHONIOENCODING"] = "utf-8"
    
    # Prepend encoding setup to ensure UTF-8 output

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

The tool accepts a free-form command parameter and forwards it to a shell unchanged, creating classic tool-parameter abuse. Because this skill is expressly intended for desktop, process, network, power, and device control, the dangerous capability is not theoretical: an attacker could supply crafted input to disable defenses, exfiltrate data, kill processes, or manipulate connected hardware.

Content

Scanner excerpt · scripts/common.py (reported line 56)May include surrounding context.

python
env["PYTHONIOENCODING"] = "utf-8"
    
    try:
        result = subprocess.run(
            command,
            capture_output=True,
            text=True,

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/iot_controller.py (reported line 251)May include surrounding context.

python
ha_tog.add_argument("--entity-id", type=str, required=True)
    
    p_ha.add_argument("--url", type=str, required=True, help="Home Assistant base URL")
    p_ha.add_argument("--token", type=str, required=True, help="Long-lived access token")

    # Generic HTTP
    p_http = sub.add_parser("http", help="Generic HTTP/REST control")

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
96% confidence
Finding

The skill declares sweeping capabilities to run local scripts, install packages, access the network, read files/screens, and control the host, but it does not define any explicit tool scope such as permissions or allowed-tools. In a high-privilege system-control skill, that omission materially increases the chance of unintended or excessive tool use, making abuse or prompt-triggered dangerous actions harder to constrain.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Many listed trigger phrases such as 'open app', 'click here', 'type text', 'screenshot', or generic control-language are common in normal conversation and are likely to collide with unrelated requests. Because this skill is privileged and can manipulate the desktop and external systems, false activations can cascade into unwanted execution or data exposure.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The documentation specifies 'Chinese OCR' via a Tesseract installation note, and many examples assume Chinese-language interaction, but the skill does not state that language selection is optional or user-driven. This can amount to a locale preference being imposed rather than offered as a choice.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
88% confidence
Finding

The skill instructs persistent modification of the environment by creating a reusable virtual environment and installing packages into it on demand. Persistent environment changes increase attack surface, complicate provenance, and can enable later executions to inherit unreviewed dependencies or altered runtime state across sessions.

Content

Scanner excerpt · SKILL.md (reported line 61)May include surrounding context.

C:\Users\wave.workbuddy\binaries\python\envs\default\Scripts\python.exe

text

If the venv does not exist, create it and install packages:

C:\Users\wave.workbuddy\binaries\python\versions\3.13.12\python.exe -m venv C:\Users\wave.workbuddy\binaries\python\envs\default C:\Users\wave.workbuddy\binaries\python\envs\default\Scripts\pip install pyautogui pillow pyserial requests

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Window close and keystroke injection can trigger unintended UI actions, dismiss prompts, submit forms, or send commands to the wrong foreground application if targeting is inaccurate. Because this skill explicitly automates desktop input, lack of warnings and safety checks materially increases the risk of accidental destructive behavior and misuse for unauthorized interaction.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Process kill commands, especially with --force, can terminate applications abruptly and cause unsaved work to be lost or leave systems in an inconsistent state. In a desktop-control skill, exposing termination commands without warning or guidance makes unintended destructive use more likely, particularly when an agent may act on ambiguous process names.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documented power and network commands can lock, sleep, hibernate, shut down, restart, or disable adapters on a live Windows system without any user-facing safety guidance. In an agent skill whose purpose is direct system control, omission of warnings and confirmation requirements increases the chance of accidental disruptive actions, data loss, or loss of connectivity during autonomous or semi-autonomous use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The IoT and HTTP examples include bearer tokens and commands that can control real-world devices or invoke arbitrary services, yet provide no warning about credential handling, plaintext transport, or the consequences of remote actions. In this skill context, the combination of network access, arbitrary REST calls, and physical-device control makes accidental or unauthorized operations more dangerous than ordinary documentation issues.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

These helpers enable direct shell and PowerShell execution without any built-in confirmation, authorization, or safety interlock for high-risk actions. In this skill context, which is explicitly designed to control software, hardware, power, network, and external devices, the absence of user-facing safeguards increases the chance of unsafe or unauthorized execution.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
89% confidence
Finding

This helper executes arbitrary PowerShell passed in via the script parameter with no validation, policy restriction, or allowlist. In a skill whose purpose is to control the host OS and devices, this creates a direct command-execution primitive that can be abused by untrusted upstream input to run destructive system commands, alter device state, or access sensitive resources.

Content

Scanner excerpt · scripts/common.py (reported line 28)May include surrounding context.

python
)
    
    try:
        result = subprocess.run(
            ["powershell", "-NoProfile", "-NonInteractive", "-Command",
             encoding_setup + script],
            capture_output=True,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
98% confidence
Finding

run_cmd invokes subprocess.run(..., shell=True), which makes the command string subject to shell parsing and command chaining. If any part of that string can be influenced by user or agent-controlled input, an attacker can execute arbitrary OS commands, pivot to persistence or data theft, and fully compromise the Windows host.

Content

Scanner excerpt · scripts/common.py (reported line 56)May include surrounding context.

python
env["PYTHONIOENCODING"] = "utf-8"
    
    try:
        result = subprocess.run(
            command,
            capture_output=True,
            text=True,

Dynamic import via __import__()

Medium
Category
Dangerous Code Execution
Confidence
75% confidence
Finding

Dynamic import() can load arbitrary modules at runtime, bypassing static analysis and potentially importing malicious code.

Content

Scanner excerpt · scripts/gui_controller.py (reported line 42)May include surrounding context.

python
missing = []
    for mod in modules:
        try:
            __import__(mod)
        except ImportError:
            missing.append(mod)
    if not missing:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Automatically installing packages without confirmation is dangerous because package installation executes code from downloaded distributions and may alter the Python environment unexpectedly. Given this skill's purpose is desktop and device control, a compromised dependency would inherit powerful local interaction capabilities, making this notably more dangerous than in a passive utility.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
94% confidence
Finding

The script automatically executes pip install at runtime, which can fetch and run untrusted package code from package indexes without any user approval, pinning, or integrity verification. In a system-control skill that already has broad desktop access, this expands the attack surface to supply-chain compromise and arbitrary code execution under the current user context.

Content

Scanner excerpt · scripts/gui_controller.py (reported line 62)May include surrounding context.

python
cmd = [pip, "-m", "pip", "install"] + pkgs
    print(f"INFO: Installing missing packages: {', '.join(pkgs)}", file=sys.stderr)
    try:
        subprocess.run(cmd, capture_output=True, timeout=120)
        return True
    except Exception as e:
        print(f"ERROR: Failed to install packages: {e}", file=sys.stderr)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The screenshot and OCR features capture potentially sensitive on-screen data and persist images to disk by default, which can expose credentials, personal data, or confidential business information to other local users, backups, or later processes. In a GUI automation skill, this is contextually sensitive because the tool is explicitly designed to observe and interact with the user's active desktop session.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Installing Python packages during execution is not necessary for core device-control behavior and expands the attack surface to package indexes and installer hooks. In a privileged automation skill, this is especially risky because a simple invocation may trigger network access and execution of newly downloaded code.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The subprocess-based package installation occurs automatically after ImportError with no interactive confirmation or opt-in flag. That means an ordinary user action can silently cause software changes to the host environment, violating least surprise and increasing the chance of unintended code execution.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
94% confidence
Finding

The script automatically invokes pip in a subprocess to install a dependency at runtime. This creates an unexpected code-execution and supply-chain risk because running the skill can fetch and execute package installation logic from external sources without explicit user approval, which is broader than the stated IoT-control purpose.

Content

Scanner excerpt · scripts/iot_controller.py (reported line 36)May include surrounding context.

python
return requests
    except ImportError:
        print("Installing requests...")
        subprocess.check_call(
            [sys.executable, "-m", "pip", "install", "requests", "-q"],
            stdout=subprocess.DEVNULL
        )

Static analysis

No suspicious patterns detected.