Security audit
Dexbox Desktop Control
Security checks for vulnerabilities and agentic risk
Overview
The skill's code, instructions, and requirements are consistent with its stated purpose of controlling dexbox-managed Windows VMs/RDP sessions; nothing in the package requests unrelated credentials, external endpoints, or unexplained install steps.
This skill appears coherent with its description, but it grants the agent the ability to send RDP credentials, take screenshots, and run arbitrary PowerShell inside guest VMs — all forwarded to a dexbox server URL (default http://localhost:8600). Before installing: 1) confirm you trust the dexbox binary source (the SKILL.md recommends 'go install' from github.com/getnenai/dexbox); 2) ensure the dexbox server runs locally and is configured to not proxy or leak data externally; 3) avoid registering highly sensitive desktops or reuse of production credentials unless you trust the server and repository; and 4) consider auditing the upstream dexbox server code/config to verify how it stores or transmits credentials and screenshots.
Static analysis
No suspicious patterns detected.
