osctrl-desktop-automation

Pass

Audited by Gen Agent Trust Hub on Mar 31, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill leverages the osctrl CLI to perform desktop automation, including mouse movements, clicks, keyboard simulation, and window management. These operations are consistent with the skill's stated purpose of automating desktop interactions.\n- [DATA_EXFILTRATION]: While the skill can perform screen captures via osctrl screen capture, there are no commands for network transmission or exfiltration of the captured data. No hardcoded credentials or access to sensitive local configuration files (e.g., SSH keys, cloud provider configs) were detected.\n- [PROMPT_INJECTION]: The skill uses osctrl context and screen capture to ingest environmental data. While this represents a potential surface for indirect prompt injection from desktop content, there is no evidence of instructions attempting to override agent safety guidelines or manipulate the agent's behavior through these inputs.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 31, 2026, 03:23 AM