Back to skill

Security audit

wine desktop automation

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for desktop automation, but it can control, screenshot, launch, close, and kill live desktop/Wine applications without clear safety boundaries.

Install only if you are comfortable giving the skill live desktop control. Run it in a dedicated test desktop or VM when possible, keep sensitive windows closed, and review any automation script before allowing launches, screenshots, window kills, process kills, or Wine prefix changes.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (36)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The documented purpose does not clearly disclose that the skill can enumerate processes, terminate processes by name or PID, bulk-kill Wine processes, restart wineserver, and inspect process state. In a desktop environment, these controls can disrupt applications, destroy unsaved work, or be abused to interfere with other workloads, making the mismatch security-relevant rather than merely cosmetic.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documented purpose does not clearly disclose that the skill can enumerate processes, terminate processes by name or PID, bulk-kill Wine processes, restart wineserver, and inspect process state. In a desktop environment, these controls can disrupt applications, destroy unsaved work, or be abused to interfere with other workloads, making the mismatch security-relevant rather than merely cosmetic.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documented purpose does not clearly disclose that the skill can enumerate processes, terminate processes by name or PID, bulk-kill Wine processes, restart wineserver, and inspect process state. In a desktop environment, these controls can disrupt applications, destroy unsaved work, or be abused to interfere with other workloads, making the mismatch security-relevant rather than merely cosmetic.

Content

No source excerpt is available for this finding.

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · scripts/wine_launcher.py (reported line 41)May include surrounding context.

python
if args:
            cmd.extend(args)

        env = os.environ.copy()
        env['WINEPREFIX'] = self._wine_prefix

        try:

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · scripts/wine_launcher.py (reported line 84)May include surrounding context.

python
if args:
            cmd.extend(args)

        env = os.environ.copy()
        env['WINEPREFIX'] = self._wine_prefix

        try:

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · scripts/wine_launcher.py (reported line 197)May include surrounding context.

python
if args:
            cmd.extend(args)

        env = os.environ.copy()
        env['WINEPREFIX'] = self._wine_prefix

        try:

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

kill_all performs bulk termination of all detected Wine processes, which is especially dangerous because it can indiscriminately disrupt multiple applications and destroy unsaved user work. This breadth is hard to justify for a desktop automation skill and materially raises the impact of any misuse or prompt injection reaching the tool.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill declares powerful capabilities related to environment access, file writing, and shell execution but does not specify any tool scope or permission boundaries. For a desktop automation skill, this omission increases the risk that downstream automation can invoke broader system actions than users expect, especially when combined with Wine launch and process-management behaviors.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The main skill content is written in Chinese and presents the skill description and usage guidance in that language, while the file does not indicate that language selection is optional or region-specific. This can violate language/locale policy when users have not opted into Chinese-language interactions.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 61)May include surrounding context.

bash
# 系统依赖(Ubuntu)
sudo apt-get install wine64 xdotool wmctrl scrot

# Python 依赖
pip install -r requirements.txt

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The code captures the screen with pyautogui.screenshot() and optionally saves the result to a file, which can expose sensitive on-screen information and persist it to disk. While the code logs when a file is saved, it does not provide a warning or explanatory comment/docstring disclosing the privacy impact of screen capture itself.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

save_template captures a screen region and saves it to a caller-specified filename, which is a file write involving potentially sensitive screen data. The function logs success but does not include a warning, docstring, or comment disclosing that it stores captured visual content on disk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill provides screenshot-triggering shortcuts (printscreen, win+printscreen) without any privacy notice, consent check, or destination control. In GUI automation, this can capture sensitive on-screen information from unrelated applications, especially because keyboard automation acts on the live desktop rather than an isolated application context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The wrapper exposes a direct ctrl+alt+delete automation primitive with no confirmation, policy check, or safety gating. In a desktop automation skill, synthesized privileged or disruptive key sequences can terminate sessions, interrupt user activity, or be chained into broader unsafe UI-driven actions if invoked on the wrong window or by untrusted input.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This module exposes direct mouse movement, clicking, dragging, and scrolling primitives that can perform destructive GUI actions without any safety interlocks, confirmation gates, target validation, or policy checks. In a desktop-automation skill, these actions can be driven by untrusted prompts or mistaken coordinates and may cause unintended clicks, data loss, application reconfiguration, or execution of sensitive actions on the host desktop.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/window_manager.py (reported line 32)May include surrounding context.

python
def _check_xdotool(self):
        try:
            subprocess.run(['xdotool', '--version'], 
                         capture_output=True, check=True)
        except (subprocess.CalledProcessError, FileNotFoundError):
            logger.error('xdotool not found. Please install it with: sudo apt-get install xdotool')

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/window_manager.py (reported line 40)May include surrounding context.

python
def _run_xdotool(self, args: List[str]) -> str:
        try:
            result = subprocess.run(['xdotool'] + args, 
                                  capture_output=True, 
                                  text=True, 
                                  check=True)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The module exposes close and kill operations that can terminate windows based on fuzzy title matching, without any confirmation, scoping, or safety checks. In a desktop automation skill, that can cause accidental data loss, disruption of unrelated applications, or abuse to interfere with user activity if an upstream prompt or caller is manipulated.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/wine_launcher.py (reported line 20)May include surrounding context.

python
def _check_wine(self):
        try:
            result = subprocess.run([self._wine_path, '--version'], 
                                  capture_output=True, 
                                  text=True, 
                                  check=True)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/window_manager.py (reported line 35)May include surrounding context.

python
check=True)
            logger.info(f'Wine version: {result.stdout.strip()}')
        except (subprocess.CalledProcessError, FileNotFoundError) as e:
            logger.error('Wine not found or not working. Please install Wine with: sudo apt-get install wine64')
            raise RuntimeError('Wine is required but not installed or not working')

    def launch(self, executable: str, args: Optional[List[str]] = None,

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/wine_launcher.py (reported line 26)May include surrounding context.

python
check=True)
            logger.info(f'Wine version: {result.stdout.strip()}')
        except (subprocess.CalledProcessError, FileNotFoundError) as e:
            logger.error('Wine not found or not working. Please install Wine with: sudo apt-get install wine64')
            raise RuntimeError('Wine is required but not installed or not working')

    def launch(self, executable: str, args: Optional[List[str]] = None,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
90% confidence
Finding

This launches an arbitrary executable and arguments through Wine based on caller-controlled input. Although it does not use a shell, it still enables execution of untrusted Windows binaries, which is especially risky in a desktop automation skill because invoking local programs is its core capability and can be abused to run malware or unsafe helper tools.

Content

Scanner excerpt · scripts/wine_launcher.py (reported line 48)May include surrounding context.

python
logger.info(f'Launching Wine application: {executable}')
            logger.debug(f'Command: {" ".join(cmd)}')
            
            process = subprocess.Popen(
                cmd,
                cwd=working_dir,
                env=env,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
92% confidence
Finding

This function constructs a Wine command from arbitrary config_options, executable, and args, then spawns it directly. Even without shell metacharacter injection, the caller can influence Wine behavior and execute untrusted code or unsafe Wine subcommands, making this a real execution-surface vulnerability in the context of an automation skill.

Content

Scanner excerpt · scripts/wine_launcher.py (reported line 91)May include surrounding context.

python
logger.info(f'Launching Wine application with config: {executable}')
            logger.debug(f'Command: {" ".join(cmd)}')
            
            process = subprocess.Popen(
                cmd,
                cwd=working_dir,
                env=env,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/wine_launcher.py (reported line 135)May include surrounding context.

python
def launch_winecfg(self) -> Optional[subprocess.Popen]:
        try:
            logger.info('Launching winecfg')
            process = subprocess.Popen(
                ['winecfg'],
                env={'WINEPREFIX': self._wine_prefix}
            )

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The code creates directories and initializes a Wine prefix on the local filesystem without any user-facing warning or confirmation. In an automation context, silent writes can surprise users, alter their local environment, and create persistence locations for later-executed Windows binaries.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.