Back to skill

Security audit

Huo15 Openclaw Desktop Control

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed macOS desktop-control guidance skill with a local installer script, not evidence of hidden or malicious behavior.

Install this only if you intentionally want OpenClaw to use macOS desktop automation with screen, accessibility, clipboard, app-control, and shell-capable MCP tools. Review the installer first if you have customized copies of this skill in OpenClaw workspaces, because rerunning it replaces that skill's existing directories.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向用户的桌面控制技能:何时触发、如何正确使用 desktop-control MCP、如何阅读状态与调用工具。但实际代码块只是一个 shell 安装脚本,作用是把该技能部署到 OpenClaw 的多个 workspace 中。两者主目的明显不同:声明强调桌面自动化能力与触发语义,代码则只做本地文件安装与目录维护。代码访问的资源也是本地文件系统与 OpenClaw 状态目录,而非桌面控制接口。因此这属于明显的描述与行为不一致。

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The trigger phrases include very broad natural-language requests like '控制电脑', '帮我点', and '帮我截屏', which can match routine user requests and cause unintended activation. Because this skill controls the desktop and can interact with apps, accidental invocation materially increases the risk of unauthorized or surprising actions on the user's machine.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The alias list contains generic terms such as '控制电脑', '自动化 macOS', '帮我点', and '看下屏幕', which are common requests rather than unique skill names. For a skill with desktop control and screenshot capability, vague aliases make unintentional activation significantly more dangerous than in a read-only or low-impact skill.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 121)May include surrounding context.

md
| `click` 完接着 `type`,没验证按钮按下生效 | act tool 全部加 `expect_after` |
| 看到 `[state]` 里 `screenshot=120s ago` 还在用旧坐标 | 先调 `screenshot` 重置截图新鲜度 |
| 用 `screenshot` + 像素识别去找按钮位置 | 优先 `find_element` 按 role/title 直接拿到中心坐标 |
| `run_command` 跑 `rm -rf` / `curl \| sh` | 桌控 guardrail 直接拒;让用户自己跑 |
| 多步操作之间不调 `get_state` 检查健康 | 每 5-10 步调一次 `get_state` 确认会话状态 |

---

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · install-to-workspaces.sh (reported line 44)May include surrounding context.

sh
# 清掉错位置残留(outer/<slug>/,单层)
  if [[ -e "$outer/$SKILL_NAME" && "$outer/$SKILL_NAME" != "$inner" ]]; then
    rm -rf "$outer/$SKILL_NAME"
    echo "  🗑  cleared stale: $outer/$SKILL_NAME"
  fi

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
80% confidence
Finding

The skill explicitly documents a shell-capable tool (run_command) but does not declare any tool scope such as permissions or allowed-tools. In a desktop automation skill, undeclared shell capability broadens the attack surface and can enable unintended command execution if the agent invokes tools beyond the user's expectation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The activation description uses an open-ended '任何' formulation for requests involving mouse, keyboard, screen viewing, or app control, without boundaries or confirmation gates. This ambiguity encourages over-activation and is particularly risky in a skill that can directly manipulate the user's desktop session.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Comments and user-facing output, including the final trigger test guidance, are written in Chinese only. This creates a language/locale policy concern because the skill does not offer an alternative language or indicate that the locale restriction is intentional and limited to a specific audience.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script unconditionally runs rm -rf on both a stale outer skill path and the target install directory before copying files. While it prints messages after deletion, there is no prior user confirmation or explicit warning in comments/docstrings that existing workspace content will be removed and replaced.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.