Back to skill

Security audit

Windows GUI 自动化集成 (中文)

Security checks for vulnerabilities and agentic risk

Overview

This Windows automation skill is purpose-aligned but needs Review because it enables broad desktop control, screenshots, AI visual analysis, and logging without enough user-control and privacy boundaries.

Review before installing. Use it only in a dedicated, least-privileged Windows session, close sensitive windows first, confirm any clicking or typing actions, and treat screenshots, OCR output, AI analysis, and logs as potentially sensitive. Pin and verify the dependent automation skills where possible.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:47
Finding

Unpinned Third-Party Automation Dependencies

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:47-50; related dependency declarations in package.json:10-16
Vulnerability Type: Unpinned and insufficiently verified third-party dependencies
Risk Level: Medium

The Skill directs users to install six external automation components without pinning reviewed versions, verifying package integrity, or validating trusted publishers.

Vulnerable code in SKILL.md:47-50:

powershell
If any dependencies are missing, run:
clawhub install windows-ui-automation win-mouse-native windows-desktop-control midscene-computer-automation windows-screenshot windows-rpa

Related declarations in package.json:10-16:

json
"peerDependencies": {
  "windows-ui-automation": ">=1.0.0",
  "win-mouse-native": ">=1.0.0",
  "windows-desktop-control": ">=1.0.0",
  "midscene-computer-automation": ">=1.0.0",
  "windows-screenshot": ">=1.0.0",
  "windows-rpa": ">=1.0.0"
}

Technical Analysis

The installation command resolves dependencies from an external package registry without specifying exact versions or integrity hashes. The corresponding peerDependencies constraints use open-ended >=1.0.0 ranges, allowing any future compatible or incompatible release above that version to satisfy the requirement.

This creates a supply-chain risk because the code ultimately executed may differ from the code reviewed when this Skill was published. Exploitation would require compromise or malicious publication of one of the named dependencies, package ownership takeover, registry compromise, or another package-resolution failure. No evidence in the audited files establishes that any current dependency is malicious.

The risk is amplified by the dependencies' intended capabilities. They provide desktop control, native mouse input, UI automation, screenshots, visual analysis, and RPA functions. Consequently, a compromised dependency could act through a high-impact inter ...[truncated 1594 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin every dependency to a specific version that has undergone security review rather than using open-ended >= constraints.
  2. Include exact versions in the documented installation command where the package manager supports that syntax.
  3. Record and verify cryptographic integrity hashes, signed package metadata, or registry provenance before installation.
  4. Verify and document the trusted publisher identity for each dependency.
  5. Establish a controlled upgrade process requiring source review, behavioral testing, and renewed integrity metadata before changing pinned versions.
  6. Audit each downstream Skill independently, especially its scripts, installation hooks, network behavior, screenshot handling, and use of desktop permissions.
  7. Run automation under a dedicated least-privileged account and avoid administrator execution unless a specific workflow requires it.
  8. Restrict access to sensitive windows and data during automation sessions, and require user confirmation before security-sensitive GUI actions.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly supports screenshots, OCR, AI visual analysis, logging, and desktop control, but the documentation does not warn users that sensitive screen contents, credentials, personal data, or enterprise information may be captured, analyzed, or stored. In a Windows GUI automation context this is particularly risky because the tool operates across arbitrary applications and can affect both confidentiality and system integrity.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases are broad everyday requests such as '桌面自动化' and '点击这个窗口', which can cause the skill to activate unintentionally for ambiguous user prompts. Because this skill can launch applications, click UI elements, type text, capture screenshots, and use AI vision, accidental invocation could lead to unintended system actions or exposure of sensitive on-screen data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The package name, description, and keywords explicitly identify the skill as Chinese-oriented ("-cn", "chinese", and Chinese-only description text), which indicates a locale/language constraint in natural-language metadata. There is no accompanying note that this is optional, user-selectable, or justified as a region-specific tool, so it appears to impose a language/locale preference without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

文件标题和元数据明确标注“中文”,全文说明也仅提供中文内容,但没有说明这是可选语言版本,或为用户提供语言/locale 选择。若组织要求技能不应默认强制单一语言而无用户选择,这种表述可能构成自然语言层面的策略不一致。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.