Back to plugin

Security audit

Dexbox Desktop Control

Security checks for vulnerabilities and agentic risk

Overview

The skill's code, instructions, and requirements are consistent with its stated purpose of controlling dexbox-managed Windows VMs/RDP sessions; nothing in the package requests unrelated credentials, external endpoints, or unexplained install steps.

This skill appears coherent with its description, but it grants the agent the ability to send RDP credentials, take screenshots, and run arbitrary PowerShell inside guest VMs — all forwarded to a dexbox server URL (default http://localhost:8600). Before installing: 1) confirm you trust the dexbox binary source (the SKILL.md recommends 'go install' from github.com/getnenai/dexbox); 2) ensure the dexbox server runs locally and is configured to not proxy or leak data externally; 3) avoid registering highly sensitive desktops or reuse of production credentials unless you trust the server and repository; and 4) consider auditing the upstream dexbox server code/config to verify how it stores or transmits credentials and screenshots.

Static analysis

No suspicious patterns detected.