pyautogui-skill

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward PyAutoGUI desktop automation skill, but it should be supervised because it can click, type, and save screenshots locally.

Install only if you need supervised desktop automation. Keep PyAutoGUI's failsafe enabled, watch automation runs, avoid unnecessary administrator privileges, and treat saved screenshots as potentially sensitive local files.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The screenshot examples save full-screen or region captures to disk without warning that screenshots may contain passwords, tokens, personal data, chats, or other sensitive on-screen information. In a desktop automation skill, this is more dangerous because the skill operates directly on a user's live desktop, making unintended data capture and later exposure plausible.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal