ToolTrust
F1787/100
tsunamayo7

helix-pilot

mcp2.0.0

@tsunamayo7

GUI automation MCP server powered by local Vision LLM (Ollama). Control your Windows desktop from Claude Code, Codex CLI, and other MCP clients.

By tsunamayo7 | 2389 findings | Scanned 6/22/2026 | tooltrust-scanner/v0.3.19 | 4

2380 High4 Low5 Info

Risk Summary

Block in Production

Supply Chain CVEs + Excessive Permissions risk is significant. Avoid using this in production agents.

Potential impact: Known dependency vulnerabilities can be exploited during install or runtime and widen the attack surface.

Recommended action: This tool should stay disabled in production agents until the flagged risks are fixed and the scan is clean.

{
  "mcpServers": {
    "helix-pilot": {
      "disabled": true
    }
  }
}

Security Findings (2389)

  • HighAS-004

    đŸ“ĻSupply Chain CVEs (OSV) ×2380

    GHSA-h8pj-cxx2-jfg2 in httpx@>=0.27.0: Improper Input Validation in httpx (upgrade to 0.23.0)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    PYSEC-2022-183 in httpx@>=0.27.0: (upgrade to 0.20.0)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    GHSA-5h2m-4q8j-pqpj in fastmcp@>=2.0.0: FastMCP OAuth Proxy token reuse across MCP servers (upgrade to 2.14.2)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    GHSA-c2jp-c369-7pvx in fastmcp@>=2.0.0: FastMCP Auth Integration Allows for Confused Deputy Account Takeover (upgrade to 2.13.0)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    GHSA-m8x7-r2rg-vh5g in fastmcp@>=2.0.0: FastMCP has a Command Injection vulnerability - Gemini CLI (upgrade to 3.2.0)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    GHSA-mxxr-jv3v-6pgc in fastmcp@>=2.0.0: FastMCP vulnerable to reflected XSS in client's callback page (upgrade to 2.13.0)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    GHSA-rcfx-77hg-w2wv in fastmcp@>=2.0.0: FastMCP updated to MCP 1.23+ due to CVE-2025-66416 (upgrade to 2.14.0)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    GHSA-rj5c-58rq-j5g5 in fastmcp@>=2.0.0: FastMCP vulnerable to windows command injection in FastMCP Cursor installer via server_name (upgrade to 2.13.0)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    GHSA-rww4-4w9c-7733 in fastmcp@>=2.0.0: FastMCP: Missing Consent Verification in OAuth Proxy Callback Facilitates Confused Deputy Vulnerabilities (upgrade to 3.2.0)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    GHSA-vv7q-7jx5-f767 in fastmcp@>=2.0.0: FastMCP OpenAPI Provider has an SSRF & Path Traversal Vulnerability (upgrade to 3.2.0)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    GHSA-2fc2-6r4j-p65h in numpy@unknown: Numpy arbitrary file write via symlink attack (upgrade to 1.8.1)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    GHSA-5545-2q6w-2gh6 in numpy@unknown: NumPy NULL Pointer Dereference (upgrade to 1.19)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    GHSA-9fq2-x9r6-wfmf in numpy@unknown: Numpy Deserialization of Untrusted Data

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    GHSA-cw6w-4rcx-xphc in numpy@unknown: Arbitrary file write in NumPy (upgrade to 1.8.1)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    GHSA-f7c7-j99h-c22f in numpy@unknown: Buffer Copy without Checking Size of Input in NumPy (upgrade to 1.19)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    GHSA-fpfv-jqm9-f5jm in numpy@unknown: Incorrect Comparison in NumPy (upgrade to 1.22)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    GHSA-frgw-fgh6-9g52 in numpy@unknown: Numpy missing input validation (upgrade to 1.13.3)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    PYSEC-2017-1 in numpy@unknown: (upgrade to 1.13.3)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    PYSEC-2018-33 in numpy@unknown: (upgrade to 0bb46c1448b0d3f5453d5182a17ea7ac5854ee15)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    PYSEC-2018-34 in numpy@unknown: (upgrade to 0bb46c1448b0d3f5453d5182a17ea7ac5854ee15)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    PYSEC-2019-108 in numpy@unknown: (upgrade to 1.16.1)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    PYSEC-2021-856 in numpy@unknown: (upgrade to 1.19.1)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    PYSEC-2021-857 in numpy@unknown: (upgrade to 1.19.0)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    GHSA-3c5c-7235-994j in pillow@unknown: Pillow buffer overflow in ImagingPcdDecode (upgrade to 3.1.1)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    GHSA-3f63-hfp8-52jq in pillow@unknown: Arbitrary Code Execution in Pillow (upgrade to 10.2.0)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    GHSA-3wvg-mj6g-m9cv in pillow@unknown: Pillow Uncontrolled Resource Consumption (upgrade to 8.1.2)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    GHSA-3xv8-3j54-hgrp in pillow@unknown: Out-of-bounds read in Pillow (upgrade to 7.1.0)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    GHSA-43fq-w8qq-v88h in pillow@unknown: Out-of-bounds read in Pillow (upgrade to 7.1.0)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    GHSA-44wm-f244-xhp3 in pillow@unknown: Pillow buffer overflow vulnerability (upgrade to 10.3.0)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    GHSA-4fx9-vc88-q2xc in pillow@unknown: Infinite loop in Pillow (upgrade to 9.0.0)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    GHSA-57h3-9rgr-c24m in pillow@unknown: Out of bounds write in Pillow (upgrade to 8.1.1)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    GHSA-5gm3-px64-rw72 in pillow@unknown: Uncontrolled Resource Consumption in Pillow (upgrade to 6.2.2)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    GHSA-7534-mm45-c74v in pillow@unknown: Buffer Overflow in Pillow (upgrade to 8.3.0)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    GHSA-7r7m-5h27-29hp in pillow@unknown: Potential infinite loop in Pillow (upgrade to 8.2.0)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    GHSA-8843-m7mw-mxqm in pillow@unknown: Buffer overflow in Pillow (upgrade to 7.1.0)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    GHSA-8ghj-p4vj-mr35 in pillow@unknown: Pillow Denial of Service vulnerability (upgrade to 10.0.0)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    GHSA-8m9x-pxwq-j236 in pillow@unknown: Pillow command injection (upgrade to 2.5.0)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    GHSA-8vj2-vxx3-667w in pillow@unknown: Arbitrary expression injection in Pillow (upgrade to 9.0.1)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    GHSA-8xjq-8fcg-g5hw in pillow@unknown: Out-of-bounds Write in Pillow (upgrade to 8.1.1)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    GHSA-8xjv-v9xq-m5h9 in pillow@unknown: Pillow Buffer overflow in ImagingFliDecode (upgrade to 3.1.1)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    GHSA-95q3-8gr9-gm8w in pillow@unknown: Pillow Denial of Service by Uncontrolled Resource Consumption (upgrade to 8.1.2)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    GHSA-9j59-75qj-795w in pillow@unknown: Path traversal in Pillow (upgrade to 9.0.1)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    GHSA-cfmr-38g9-f2h7 in pillow@unknown: Pillow denial of service via Crafted Block Size (upgrade to 2.3.2)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    GHSA-cqhg-xjhh-p8hf in pillow@unknown: Out-of-bounds reads in Pillow (upgrade to 7.1.0)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    GHSA-f4w8-cv6p-x6r5 in pillow@unknown: Pillow Denial of Service by Uncontrolled Resource Consumption (upgrade to 8.1.2)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    GHSA-f5g8-5qq7-938w in pillow@unknown: Pillow Out-of-bounds Read (upgrade to 8.1.0)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    GHSA-g6rj-rv7j-xwp4 in pillow@unknown: Pillow denial of service (upgrade to 8.2.0)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    GHSA-h5rf-vgqx-wjv2 in pillow@unknown: Pillow denial of service via PNG bomb (upgrade to 2.7.0)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    GHSA-hggx-3h72-49ww in pillow@unknown: Pillow Buffer overflow in ImagingLibTiffDecode (upgrade to 3.1.1)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    GHSA-hj69-c76v-86wr in pillow@unknown: Out-of-bounds Read in Pillow (upgrade to 6.2.2)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    GHSA-hvr8-466p-75rh in pillow@unknown: Pillow Integer overflow in ImagingResampleHorizontal (upgrade to 3.1.1)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    GHSA-j6f7-g425-4gmx in pillow@unknown: Pillow is vulnerable to Denial of Service (DOS) in the Jpeg2KImagePlugin (upgrade to 2.5.3)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    GHSA-j7hp-h8jx-5ppr in pillow@unknown: libwebp: OOB write in BuildHuffmanTable (upgrade to 0.1.8)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    GHSA-j7mj-748x-7p78 in pillow@unknown: DOS attack in Pillow when processing specially crafted image files (upgrade to 6.2.0)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    GHSA-jgpv-4h4c-xhw3 in pillow@unknown: Uncontrolled Resource Consumption in pillow (upgrade to 8.1.2)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    GHSA-m2vv-5vj5-2hm7 in pillow@unknown: Pillow vulnerable to Data Amplification attack. (upgrade to 9.2.0)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    GHSA-mvg9-xffr-p774 in pillow@unknown: Out of bounds read in Pillow (upgrade to 8.2.0)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    GHSA-p49h-hjvm-jg3h in pillow@unknown: PCX P mode buffer overflow in Pillow (upgrade to 6.2.2)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    GHSA-pw3c-h7wp-cvhx in pillow@unknown: Improper Initialization in Pillow (upgrade to 9.0.0)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    GHSA-q5hq-fp76-qmrc in pillow@unknown: Uncontrolled Resource Consumption in Pillow (upgrade to 8.2.0)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    GHSA-r7rm-8j6h-r933 in pillow@unknown: Buffer Copy without Checking Size of Input in Pillow (upgrade to 6.2.2)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    GHSA-r854-96gq-rfg3 in pillow@unknown: Pillow Temporary file name leakage (upgrade to 2.3.1)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    GHSA-rwr3-c2q8-gm56 in pillow@unknown: Pillow Integer overflow in Map.c (upgrade to 3.3.2)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    GHSA-vcqg-3p29-xw73 in pillow@unknown: Integer overflow in Pillow (upgrade to 6.2.2)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    GHSA-vj42-xq3r-hr3r in pillow@unknown: Out-of-bounds reads in Pillow (upgrade to 7.1.0)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    GHSA-vqcj-wrf2-7v73 in pillow@unknown: Pillow Out-of-bounds Write (upgrade to 8.1.0)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    GHSA-w4vg-rf63-f3j3 in pillow@unknown: Arbitrary code using "crafted image file" approach affecting Pillow (upgrade to 3.3.2)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    GHSA-wjx4-4jcj-g98j in pillow@unknown: Pillow has an integer overflow when processing fonts (upgrade to 12.2.0)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    GHSA-x895-2wrm-hvp7 in pillow@unknown: PIL and Pillow Vulnerable to Symlink Attack on Tmpfiles (upgrade to 2.3.1)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    GHSA-xrcv-f9gm-v42c in pillow@unknown: Out-of-bounds Read in Pillow (upgrade to 9.0.0)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    PYSEC-2014-10 in pillow@unknown: (upgrade to 205e056f8f9b06ed7b925cf8aa0874bc4aaf8a7d)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    PYSEC-2014-22 in pillow@unknown: (upgrade to 4e9f367dfd3f04c8f5d23f7f759ec12782e10ee7)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    PYSEC-2014-23 in pillow@unknown: (upgrade to 4e9f367dfd3f04c8f5d23f7f759ec12782e10ee7)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    PYSEC-2014-87 in pillow@unknown: (upgrade to 2.5.0)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    PYSEC-2015-15 in pillow@unknown: (upgrade to 2.5.3)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    PYSEC-2015-16 in pillow@unknown: (upgrade to 2.7.0)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    PYSEC-2016-19 in pillow@unknown: (upgrade to 5bdf54b5a76b54fb00bd05f2d733e0a4173eefc9)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    PYSEC-2016-5 in pillow@unknown: (upgrade to 6dcbf5bd96b717c58d7b642949da8d323099928e)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    PYSEC-2016-6 in pillow@unknown: (upgrade to 893a40850c2d5da41537958e40569c029a6e127b)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    PYSEC-2016-7 in pillow@unknown: (upgrade to 4e0d9b0b9740d258ade40cce248c93777362ac1e)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    PYSEC-2016-8 in pillow@unknown: (upgrade to 3.3.2)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    PYSEC-2016-9 in pillow@unknown: (upgrade to 3.3.2)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    PYSEC-2019-110 in pillow@unknown: (upgrade to 6.2.0)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    PYSEC-2020-172 in pillow@unknown: (upgrade to 6.2.2)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    PYSEC-2020-76 in pillow@unknown: (upgrade to 7.1.0)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    PYSEC-2020-77 in pillow@unknown: (upgrade to 6a83e4324738bb0452fbe8074a995b1c73f08de7)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    PYSEC-2020-78 in pillow@unknown: (upgrade to 46f4a349b88915787fea3fb91348bb1665831bbb)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    PYSEC-2020-79 in pillow@unknown: (upgrade to 7.0.0)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    PYSEC-2020-80 in pillow@unknown: (upgrade to 7.1.0)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    PYSEC-2020-81 in pillow@unknown: (upgrade to 4e2def2539ec13e53a82e06c4b3daf00454100c4)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    PYSEC-2020-82 in pillow@unknown: (upgrade to a79b65c47c7dc6fe623aadf09aa6192fc54548f3)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    PYSEC-2020-83 in pillow@unknown: (upgrade to 93b22b846e0269ee9594ff71a72bec02d2bea8fd)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    PYSEC-2020-84 in pillow@unknown: (upgrade to a09acd0decd8a87ccce939d5ff65dab59e7d365b)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    PYSEC-2021-137 in pillow@unknown: (upgrade to 8.2.0)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    PYSEC-2021-138 in pillow@unknown: (upgrade to 8.2.0)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    PYSEC-2021-139 in pillow@unknown: (upgrade to 8.2.0)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    PYSEC-2021-317 in pillow@unknown: (upgrade to 9e08eb8f78fdfd2f476e1b20b7cf38683754866b)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    PYSEC-2021-331 in pillow@unknown: (upgrade to 8.3.0)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    PYSEC-2021-35 in pillow@unknown: (upgrade to 8.1.1)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    PYSEC-2021-36 in pillow@unknown: (upgrade to 8.1.1)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    PYSEC-2021-37 in pillow@unknown: (upgrade to 8.1.1)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    PYSEC-2021-38 in pillow@unknown: (upgrade to 8.1.1)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    PYSEC-2021-39 in pillow@unknown: (upgrade to 8.1.1)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    PYSEC-2021-40 in pillow@unknown: (upgrade to 8.1.1)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    PYSEC-2021-41 in pillow@unknown: (upgrade to 8.1.1)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    PYSEC-2021-42 in pillow@unknown: (upgrade to 8.1.1)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    PYSEC-2021-69 in pillow@unknown: (upgrade to 8.1.0)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    PYSEC-2021-70 in pillow@unknown: (upgrade to 8.1.0)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    PYSEC-2021-92 in pillow@unknown: (upgrade to 8.2.0)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    PYSEC-2021-93 in pillow@unknown: (upgrade to 8.2.0)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    PYSEC-2021-94 in pillow@unknown: (upgrade to 8.2.0)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    PYSEC-2022-10 in pillow@unknown: (upgrade to 9.0.0)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    PYSEC-2022-168 in pillow@unknown: (upgrade to 9.0.1)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    PYSEC-2022-42979 in pillow@unknown: (upgrade to 11918eac0628ec8ac0812670d9838361ead2d6a4)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    PYSEC-2022-8 in pillow@unknown: (upgrade to 9.0.0)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    PYSEC-2022-9 in pillow@unknown: (upgrade to 9.0.0)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    PYSEC-2023-175 in pillow@unknown: (upgrade to 10.0.1)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    PYSEC-2023-227 in pillow@unknown: (upgrade to 1fe1bb49c452b0318cad12ea9d97c3bef188e9a7)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    PYSEC-2026-165 in pillow@unknown: (upgrade to 12.2.0)

    screenshotclicktype_texthotkeyscrolldescribefindverifystatuslist_windowswait_stableautobrowseclick_screenshotresize_imagespawn_pilot_agentsend_pilot_agent_inputwait_pilot_agentlist_pilot_agentsclose_pilot_agent

    Fix: Upgrade or replace the vulnerable dependency. Pin all dependency versions and enable automated CVE scanning (Dependabot or OSV Scanner).

  • LowAS-011

    â„šī¸Missing Rate-Limit / Timeout ×4

    tool performs network or execution operations but declares no rate-limit, timeout, or retry configuration

    findautobrowsespawn_pilot_agent

    Fix: Declare explicit rate-limit, timeout, and retry configuration for all network and execution tools. Implement exponential back-off and surface resource state to the calling agent.

  • InfoAS-002

    âš ī¸Excessive Permissions ×5

    declared capabilities: code/command execution

    findautobrowsespawn_pilot_agent

    declared capabilities: filesystem access

    resize_image

    Fix: Tool requests broad permissions (exec/fs/network). Validate input parameters using Enums where possible, and restrict file system operations to explicit allowed directories.

Scan this tool yourself

Reproduce this audit locally, integrate into CI, or let your agent audit its own tools.

Install once, then scan any MCP server:

$ curl -sfL https://raw.githubusercontent.com/AgentSafe-AI/tooltrust-scanner/main/install.sh | bash
$ tooltrust-scanner scan --server "npx -y helix-pilot"

Adjust the package name if your npm registry name differs from the tool ID. View source

Add badge to your README

Copy this Markdown to show your ToolTrust grade on GitHub.

[![ToolTrust Grade F](https://raw.githubusercontent.com/AgentSafe-AI/tooltrust-directory/main/docs/badges/grade-f.svg)](https://github.com/AgentSafe-AI/tooltrust-directory)