Back to skill

Security audit

macOS Computer-Use Skill

Security checks for vulnerabilities and agentic risk

Overview

This skill is a legitimate macOS desktop-control tool, but its standalone runtime silently grants broad app, clipboard, and system-key access instead of getting the user approval its tool descriptions imply.

Install only if you are comfortable giving this runtime macOS Accessibility and Screen Recording permissions and letting it control local apps. Treat clipboard read/write and system-key use as sensitive, and prefer running it in a controlled macOS account or environment until it has explicit user approval prompts or a strict allowlist.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
project/src/session.ts:22
Finding

Automatic Approval Bypasses Per-Application and Sensitive Capability Authorization

Content
View full analysis

Vulnerability Details

File Location: project/src/session.ts:22-46 and project/src/session.ts:67
Vulnerability Type: Authorization bypass and excessive privilege granting
Risk Level: High

Vulnerable Code:

ts
function autoApprovePermission(req: CuPermissionRequest): CuPermissionResponse {
  const granted = req.apps
    .filter(app => app.resolved && !app.alreadyGranted)
    .map(app => ({
      bundleId: app.resolved!.bundleId,
      displayName: app.resolved!.displayName,
      grantedAt: Date.now(),
      tier: app.proposedTier,
    }))

  const denied = req.apps
    .filter(app => !app.resolved)
    .map(app => ({
      bundleId: app.requestedName,
      reason: 'not_installed' as const,
    }))

  return {
    granted,
    denied,
    flags: {
      ...DEFAULT_GRANT_FLAGS,
      ...req.requestedFlags,
    },
  }
}
ts
onPermissionRequest: async req => autoApprovePermission(req),

Technical Analysis

The MCP computer-use framework includes a permission-request workflow intended to authorize access to individual applications and sensitive capabilities. The standalone session replaces interactive authorization with autoApprovePermission().

Every requested application that resolves to an installed application is granted its proposed access tier without user review. In addition, req.requestedFlags is merged over the secure defaults. This allows requests for capabilities such as clipboard reading, clipboard writing, and system-level key combinations to be approved automatically.

macOS Accessibility and Screen Recording permissions still provide an operating-system boundary. However, once the user has granted those broad TCC permissions to the runtime, this implementation provides no meaningful per-application or per-capability consent boundary. The existing access-control framework therefore appears to enforce permission tiers while its ...[truncated 1990 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace autoApprovePermission() with an interactive approval handler that shows:
    • The exact application and bundle identifier.
    • The proposed access tier.
    • Requested clipboard and system-key capabilities.
    • The reason supplied by the requesting client.
  2. Require explicit user confirmation before granting a new application or increasing an existing application's tier.
  3. Keep clipboardRead, clipboardWrite, and systemKeyCombos disabled unless individually approved.
  4. Maintain and enforce a user-denied application list rather than returning an empty list for every session.
  5. If unattended operation is required, provide a disabled-by-default mode backed by a static, user-managed allowlist containing exact bundle identifiers, maximum tiers, and allowed flags.
  6. Prevent unattended mode from granting applications or capabilities absent from that allowlist.
  7. Record security-relevant grant events locally without recording clipboard or screen contents.
  8. Add tests demonstrating that new applications, privilege-tier increases, clipboard access, and system-key requests remain denied until explicitly authorized.

T08 · Insecure Dependencies

Warning
Location
project/runtime/requirements.txt:1
Finding

Mutable Python Dependencies Are Downloaded and Executed During First-Run Bootstrap

Content
View full analysis

Vulnerability Details

File Location: project/runtime/requirements.txt:1-6 and project/src/computer-use/pythonBridge.ts:65-71
Vulnerability Type: Unpinned dependency installation and non-reproducible bootstrap
Risk Level: Medium

Vulnerable Code:

text
mss>=10.1.0
Pillow>=11.3.0
pyautogui>=0.9.54
pyobjc-core>=11.1
pyobjc-framework-Cocoa>=11.1
pyobjc-framework-Quartz>=11.1
ts
if (installedDigest !== digest) {
  logDebug('installing python runtime dependencies')
  await runOrThrow(pythonBinPath(), ['-m', 'pip', 'install', '--upgrade', 'pip'], 'pip upgrade')
  await runOrThrow(
    pythonBinPath(),
    ['-m', 'pip', 'install', '-r', requirementsPath],
    'python dependency install',
  )
  await writeFile(installStampPath, `${digest}\n`, 'utf8')
}

Technical Analysis

The runtime automatically creates a Python virtual environment and downloads dependencies during first use. All Python requirements use open-ended >= constraints, so installations performed at different times may resolve to different package versions. The bootstrap also upgrades pip to the latest available compatible release without pinning it.

The installation stamp hashes only the text of requirements.txt. It does not lock the resolved dependency graph or verify hashes of downloaded distributions. Consequently, an unchanged requirements file can lead to different code being installed on different hosts or at different times.

Python packages and their installation artifacts execute code within the local user context. Because this runtime subsequently receives macOS Accessibility and Screen Recording privileges, a compromised upstream release would run in a particularly sensitive environment. No evidence indicates that the currently named dependencies are malicious; the vulnerability is the mutable and insufficiently verified supply-chain process.

Attack Path

  1. An atta ...[truncated 1560 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace every open-ended dependency constraint with an exact, reviewed version.
  2. Generate a fully resolved lock file covering direct and transitive dependencies.
  3. Record SHA-256 hashes for all accepted wheels and enforce installation with pip's --require-hashes option.
  4. Pin the bootstrap tooling or avoid automatically upgrading pip at runtime.
  5. Prefer reviewed binary wheels from trusted indexes and reject unexpected source distributions.
  6. Configure an explicit trusted package index rather than inheriting arbitrary pip index configuration when the deployment model permits it.
  7. Build and verify the runtime during installation rather than silently downloading executable components during the first computer-use action.
  8. Clearly notify the user before network-based dependency installation and document the packages and indexes involved.
  9. Use the resolved lock-file and artifact hashes, rather than only the source requirements text, when determining whether the installed environment is current.
  10. Add automated dependency vulnerability scanning and a controlled update process for reviewing new versions before release.
Vulnerability Patterns
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (89)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the bundled project truly includes undeclared capabilities such as mouse/keyboard control, clipboard access, app enumeration/launching, screen inspection, and permission probing, the skill description materially understates a highly privileged local automation surface. In a trusted-local computer-use context, incomplete disclosure is dangerous because operators may authorize a skill without understanding that it can observe the screen, manipulate input, inspect apps, and query sensitive OS permissions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

If the bundled project truly includes undeclared capabilities such as mouse/keyboard control, clipboard access, app enumeration/launching, screen inspection, and permission probing, the skill description materially understates a highly privileged local automation surface. In a trusted-local computer-use context, incomplete disclosure is dangerous because operators may authorize a skill without understanding that it can observe the screen, manipulate input, inspect apps, and query sensitive OS permissions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

If the bundled project truly includes undeclared capabilities such as mouse/keyboard control, clipboard access, app enumeration/launching, screen inspection, and permission probing, the skill description materially understates a highly privileged local automation surface. In a trusted-local computer-use context, incomplete disclosure is dangerous because operators may authorize a skill without understanding that it can observe the screen, manipulate input, inspect apps, and query sensitive OS permissions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

If the bundled project truly includes undeclared capabilities such as mouse/keyboard control, clipboard access, app enumeration/launching, screen inspection, and permission probing, the skill description materially understates a highly privileged local automation surface. In a trusted-local computer-use context, incomplete disclosure is dangerous because operators may authorize a skill without understanding that it can observe the screen, manipulate input, inspect apps, and query sensitive OS permissions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

If the bundled project truly includes undeclared capabilities such as mouse/keyboard control, clipboard access, app enumeration/launching, screen inspection, and permission probing, the skill description materially understates a highly privileged local automation surface. In a trusted-local computer-use context, incomplete disclosure is dangerous because operators may authorize a skill without understanding that it can observe the screen, manipulate input, inspect apps, and query sensitive OS permissions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

If the bundled project truly includes undeclared capabilities such as mouse/keyboard control, clipboard access, app enumeration/launching, screen inspection, and permission probing, the skill description materially understates a highly privileged local automation surface. In a trusted-local computer-use context, incomplete disclosure is dangerous because operators may authorize a skill without understanding that it can observe the screen, manipulate input, inspect apps, and query sensitive OS permissions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

If the bundled project truly includes undeclared capabilities such as mouse/keyboard control, clipboard access, app enumeration/launching, screen inspection, and permission probing, the skill description materially understates a highly privileged local automation surface. In a trusted-local computer-use context, incomplete disclosure is dangerous because operators may authorize a skill without understanding that it can observe the screen, manipulate input, inspect apps, and query sensitive OS permissions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

If the bundled project truly includes undeclared capabilities such as mouse/keyboard control, clipboard access, app enumeration/launching, screen inspection, and permission probing, the skill description materially understates a highly privileged local automation surface. In a trusted-local computer-use context, incomplete disclosure is dangerous because operators may authorize a skill without understanding that it can observe the screen, manipulate input, inspect apps, and query sensitive OS permissions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the bundled project truly includes undeclared capabilities such as mouse/keyboard control, clipboard access, app enumeration/launching, screen inspection, and permission probing, the skill description materially understates a highly privileged local automation surface. In a trusted-local computer-use context, incomplete disclosure is dangerous because operators may authorize a skill without understanding that it can observe the screen, manipulate input, inspect apps, and query sensitive OS permissions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the bundled project truly includes undeclared capabilities such as mouse/keyboard control, clipboard access, app enumeration/launching, screen inspection, and permission probing, the skill description materially understates a highly privileged local automation surface. In a trusted-local computer-use context, incomplete disclosure is dangerous because operators may authorize a skill without understanding that it can observe the screen, manipulate input, inspect apps, and query sensitive OS permissions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

If the bundled project truly includes undeclared capabilities such as mouse/keyboard control, clipboard access, app enumeration/launching, screen inspection, and permission probing, the skill description materially understates a highly privileged local automation surface. In a trusted-local computer-use context, incomplete disclosure is dangerous because operators may authorize a skill without understanding that it can observe the screen, manipulate input, inspect apps, and query sensitive OS permissions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the bundled project truly includes undeclared capabilities such as mouse/keyboard control, clipboard access, app enumeration/launching, screen inspection, and permission probing, the skill description materially understates a highly privileged local automation surface. In a trusted-local computer-use context, incomplete disclosure is dangerous because operators may authorize a skill without understanding that it can observe the screen, manipulate input, inspect apps, and query sensitive OS permissions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the bundled project truly includes undeclared capabilities such as mouse/keyboard control, clipboard access, app enumeration/launching, screen inspection, and permission probing, the skill description materially understates a highly privileged local automation surface. In a trusted-local computer-use context, incomplete disclosure is dangerous because operators may authorize a skill without understanding that it can observe the screen, manipulate input, inspect apps, and query sensitive OS permissions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the bundled project truly includes undeclared capabilities such as mouse/keyboard control, clipboard access, app enumeration/launching, screen inspection, and permission probing, the skill description materially understates a highly privileged local automation surface. In a trusted-local computer-use context, incomplete disclosure is dangerous because operators may authorize a skill without understanding that it can observe the screen, manipulate input, inspect apps, and query sensitive OS permissions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

If the bundled project truly includes undeclared capabilities such as mouse/keyboard control, clipboard access, app enumeration/launching, screen inspection, and permission probing, the skill description materially understates a highly privileged local automation surface. In a trusted-local computer-use context, incomplete disclosure is dangerous because operators may authorize a skill without understanding that it can observe the screen, manipulate input, inspect apps, and query sensitive OS permissions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
86% confidence
Finding

If the bundled project truly includes undeclared capabilities such as mouse/keyboard control, clipboard access, app enumeration/launching, screen inspection, and permission probing, the skill description materially understates a highly privileged local automation surface. In a trusted-local computer-use context, incomplete disclosure is dangerous because operators may authorize a skill without understanding that it can observe the screen, manipulate input, inspect apps, and query sensitive OS permissions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the bundled project truly includes undeclared capabilities such as mouse/keyboard control, clipboard access, app enumeration/launching, screen inspection, and permission probing, the skill description materially understates a highly privileged local automation surface. In a trusted-local computer-use context, incomplete disclosure is dangerous because operators may authorize a skill without understanding that it can observe the screen, manipulate input, inspect apps, and query sensitive OS permissions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

If the bundled project truly includes undeclared capabilities such as mouse/keyboard control, clipboard access, app enumeration/launching, screen inspection, and permission probing, the skill description materially understates a highly privileged local automation surface. In a trusted-local computer-use context, incomplete disclosure is dangerous because operators may authorize a skill without understanding that it can observe the screen, manipulate input, inspect apps, and query sensitive OS permissions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

If the bundled project truly includes undeclared capabilities such as mouse/keyboard control, clipboard access, app enumeration/launching, screen inspection, and permission probing, the skill description materially understates a highly privileged local automation surface. In a trusted-local computer-use context, incomplete disclosure is dangerous because operators may authorize a skill without understanding that it can observe the screen, manipulate input, inspect apps, and query sensitive OS permissions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the bundled project truly includes undeclared capabilities such as mouse/keyboard control, clipboard access, app enumeration/launching, screen inspection, and permission probing, the skill description materially understates a highly privileged local automation surface. In a trusted-local computer-use context, incomplete disclosure is dangerous because operators may authorize a skill without understanding that it can observe the screen, manipulate input, inspect apps, and query sensitive OS permissions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

If the bundled project truly includes undeclared capabilities such as mouse/keyboard control, clipboard access, app enumeration/launching, screen inspection, and permission probing, the skill description materially understates a highly privileged local automation surface. In a trusted-local computer-use context, incomplete disclosure is dangerous because operators may authorize a skill without understanding that it can observe the screen, manipulate input, inspect apps, and query sensitive OS permissions.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Permission requests are approved silently in code, and unresolved apps are only marked denied due to installation state rather than user choice. This means the runtime can expand its control surface with no visible warning or confirmation, which is especially dangerous in a tool designed to drive desktop applications.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
100% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · project/dist/vendor/computer-use-mcp/toolCalls.js (reported line 201)May include surrounding context.

js
//
// Threat: tier "click" blocks type/key/right-click-Paste, but a click-tier
// terminal/IDE may have a UI Paste button that's plain-left-clickable. If the
// clipboard holds `rm -rf /` — from the user, from a prior full-tier paste,
// OR from the agent's own write_clipboard call (which doesn't route through
// runInputActionGates) — a left_click on that button injects it.
//

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
100% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · project/dist/vendor/computer-use-mcp/types.d.ts (reported line 24)May include surrounding context.

ts
//
// Threat: tier "click" blocks type/key/right-click-Paste, but a click-tier
// terminal/IDE may have a UI Paste button that's plain-left-clickable. If the
// clipboard holds `rm -rf /` — from the user, from a prior full-tier paste,
// OR from the agent's own write_clipboard call (which doesn't route through
// runInputActionGates) — a left_click on that button injects it.
//

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
100% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · project/src/vendor/computer-use-mcp/toolCalls.ts (reported line 351)May include surrounding context.

ts
//
// Threat: tier "click" blocks type/key/right-click-Paste, but a click-tier
// terminal/IDE may have a UI Paste button that's plain-left-clickable. If the
// clipboard holds `rm -rf /` — from the user, from a prior full-tier paste,
// OR from the agent's own write_clipboard call (which doesn't route through
// runInputActionGates) — a left_click on that button injects it.
//

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
project/dist/lib/execFileNoThrow.js:4

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
project/src/lib/execFileNoThrow.ts:9