T09 · Insecure Skill Coding Practices
- Location
scripts/process_manager.py:99- Finding
PowerShell Command Injection in Process Startup
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is not clearly malicious, but it grants broad control over a Windows desktop, devices, network, screenshots, and smart-home APIs with weak implementation safeguards.
Install only if you intentionally want an agent to control your Windows desktop and connected devices. Use a dedicated, least-privileged environment, require explicit confirmation before state-changing actions, avoid passing long-lived tokens on command lines or over HTTP, and treat saved screenshots/OCR files as potentially sensitive.
scripts/process_manager.py:99PowerShell Command Injection in Process Startup
scripts/window_manager.py:270PowerShell Command Injection Through Window Text and Title Arguments
scripts/hardware_controller.py:240PowerShell Expression Injection Through Network Adapter Names
scripts/iot_controller.py:46Home Assistant Tokens Exposed in Command Lines and Permitted Over Plaintext HTTP
scripts/iot_controller.py:27Unpinned Runtime Installation of Third-Party Packages
scripts/gui_controller.py:297Sensitive OCR Screenshot Stored in a Predictable Temporary File
The description substantially overstates the skill’s scope. The supplied code is narrowly focused on GUI automation and screen-based interaction: moving/clicking/dragging the mouse, typing/pressing keys, taking screenshots, OCR, finding images, clicking images, and reading pixel colors. Those parts do match the description. However, the declared purpose also claims broad control over Windows software, hardware, and IoT devices, including process management, system volume/brightness, power actions, network adapters, serial/Arduino communication, USB devices, and smart home platforms. None of those capabilities are present in this code chunk. Because the declared description presents these as core supported uses rather than optional adjacent features, it does not accurately represent what this code actually does.
The trigger scope is extremely broad, covering essentially any request about controlling software, hardware, or external devices. In a skill that can perform process management, GUI automation, power operations, networking, screenshots/OCR, and IoT/API calls, overbroad routing can cause accidental invocation on ambiguous everyday requests and lead to unintended high-impact actions.
Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.
4. **Never disable critical network adapters** (the one used for active internet connection) without warning.
Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.
Execute PowerShell script with proper encoding handling.
Returns (stdout: str, stderr: str, returncode: int)
"""
env = os.environ.copy()
env["PYTHONIOENCODING"] = "utf-8"
# Prepend encoding setup to ensure UTF-8 output
Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.
Execute PowerShell script with proper encoding handling.
Returns (stdout: str, stderr: str, returncode: int)
"""
env = os.environ.copy()
env["PYTHONIOENCODING"] = "utf-8"
# Prepend encoding setup to ensure UTF-8 output
The tool accepts a free-form command parameter and forwards it to a shell unchanged, creating classic tool-parameter abuse. Because this skill is expressly intended for desktop, process, network, power, and device control, the dangerous capability is not theoretical: an attacker could supply crafted input to disable defenses, exfiltrate data, kill processes, or manipulate connected hardware.
env["PYTHONIOENCODING"] = "utf-8"
try:
result = subprocess.run(
command,
capture_output=True,
text=True,
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
ha_tog.add_argument("--entity-id", type=str, required=True)
p_ha.add_argument("--url", type=str, required=True, help="Home Assistant base URL")
p_ha.add_argument("--token", type=str, required=True, help="Long-lived access token")
# Generic HTTP
p_http = sub.add_parser("http", help="Generic HTTP/REST control")
The skill declares sweeping capabilities to run local scripts, install packages, access the network, read files/screens, and control the host, but it does not define any explicit tool scope such as permissions or allowed-tools. In a high-privilege system-control skill, that omission materially increases the chance of unintended or excessive tool use, making abuse or prompt-triggered dangerous actions harder to constrain.
Many listed trigger phrases such as 'open app', 'click here', 'type text', 'screenshot', or generic control-language are common in normal conversation and are likely to collide with unrelated requests. Because this skill is privileged and can manipulate the desktop and external systems, false activations can cascade into unwanted execution or data exposure.
The documentation specifies 'Chinese OCR' via a Tesseract installation note, and many examples assume Chinese-language interaction, but the skill does not state that language selection is optional or user-driven. This can amount to a locale preference being imposed rather than offered as a choice.
The skill instructs persistent modification of the environment by creating a reusable virtual environment and installing packages into it on demand. Persistent environment changes increase attack surface, complicate provenance, and can enable later executions to inherit unreviewed dependencies or altered runtime state across sessions.
C:\Users\wave.workbuddy\binaries\python\envs\default\Scripts\python.exe
If the venv does not exist, create it and install packages:
C:\Users\wave.workbuddy\binaries\python\versions\3.13.12\python.exe -m venv C:\Users\wave.workbuddy\binaries\python\envs\default C:\Users\wave.workbuddy\binaries\python\envs\default\Scripts\pip install pyautogui pillow pyserial requests
Window close and keystroke injection can trigger unintended UI actions, dismiss prompts, submit forms, or send commands to the wrong foreground application if targeting is inaccurate. Because this skill explicitly automates desktop input, lack of warnings and safety checks materially increases the risk of accidental destructive behavior and misuse for unauthorized interaction.
Process kill commands, especially with --force, can terminate applications abruptly and cause unsaved work to be lost or leave systems in an inconsistent state. In a desktop-control skill, exposing termination commands without warning or guidance makes unintended destructive use more likely, particularly when an agent may act on ambiguous process names.
The documented power and network commands can lock, sleep, hibernate, shut down, restart, or disable adapters on a live Windows system without any user-facing safety guidance. In an agent skill whose purpose is direct system control, omission of warnings and confirmation requirements increases the chance of accidental disruptive actions, data loss, or loss of connectivity during autonomous or semi-autonomous use.
The IoT and HTTP examples include bearer tokens and commands that can control real-world devices or invoke arbitrary services, yet provide no warning about credential handling, plaintext transport, or the consequences of remote actions. In this skill context, the combination of network access, arbitrary REST calls, and physical-device control makes accidental or unauthorized operations more dangerous than ordinary documentation issues.
These helpers enable direct shell and PowerShell execution without any built-in confirmation, authorization, or safety interlock for high-risk actions. In this skill context, which is explicitly designed to control software, hardware, power, network, and external devices, the absence of user-facing safeguards increases the chance of unsafe or unauthorized execution.
This helper executes arbitrary PowerShell passed in via the script parameter with no validation, policy restriction, or allowlist. In a skill whose purpose is to control the host OS and devices, this creates a direct command-execution primitive that can be abused by untrusted upstream input to run destructive system commands, alter device state, or access sensitive resources.
)
try:
result = subprocess.run(
["powershell", "-NoProfile", "-NonInteractive", "-Command",
encoding_setup + script],
capture_output=True,
run_cmd invokes subprocess.run(..., shell=True), which makes the command string subject to shell parsing and command chaining. If any part of that string can be influenced by user or agent-controlled input, an attacker can execute arbitrary OS commands, pivot to persistence or data theft, and fully compromise the Windows host.
env["PYTHONIOENCODING"] = "utf-8"
try:
result = subprocess.run(
command,
capture_output=True,
text=True,
Dynamic import() can load arbitrary modules at runtime, bypassing static analysis and potentially importing malicious code.
missing = []
for mod in modules:
try:
__import__(mod)
except ImportError:
missing.append(mod)
if not missing:
Automatically installing packages without confirmation is dangerous because package installation executes code from downloaded distributions and may alter the Python environment unexpectedly. Given this skill's purpose is desktop and device control, a compromised dependency would inherit powerful local interaction capabilities, making this notably more dangerous than in a passive utility.
The script automatically executes pip install at runtime, which can fetch and run untrusted package code from package indexes without any user approval, pinning, or integrity verification. In a system-control skill that already has broad desktop access, this expands the attack surface to supply-chain compromise and arbitrary code execution under the current user context.
cmd = [pip, "-m", "pip", "install"] + pkgs
print(f"INFO: Installing missing packages: {', '.join(pkgs)}", file=sys.stderr)
try:
subprocess.run(cmd, capture_output=True, timeout=120)
return True
except Exception as e:
print(f"ERROR: Failed to install packages: {e}", file=sys.stderr)
The screenshot and OCR features capture potentially sensitive on-screen data and persist images to disk by default, which can expose credentials, personal data, or confidential business information to other local users, backups, or later processes. In a GUI automation skill, this is contextually sensitive because the tool is explicitly designed to observe and interact with the user's active desktop session.
Installing Python packages during execution is not necessary for core device-control behavior and expands the attack surface to package indexes and installer hooks. In a privileged automation skill, this is especially risky because a simple invocation may trigger network access and execution of newly downloaded code.
The subprocess-based package installation occurs automatically after ImportError with no interactive confirmation or opt-in flag. That means an ordinary user action can silently cause software changes to the host environment, violating least surprise and increasing the chance of unintended code execution.
The script automatically invokes pip in a subprocess to install a dependency at runtime. This creates an unexpected code-execution and supply-chain risk because running the skill can fetch and execute package installation logic from external sources without explicit user approval, which is broader than the stated IoT-control purpose.
return requests
except ImportError:
print("Installing requests...")
subprocess.check_call(
[sys.executable, "-m", "pip", "install", "requests", "-q"],
stdout=subprocess.DEVNULL
)
No suspicious patterns detected.