windows-qa-engineer

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill's installer (scripts/skill_installer.py) fetches the Microsoft UFO framework from its official GitHub repository (https://github.com/microsoft/UFO.git) and installs necessary dependencies via pip.
  • [COMMAND_EXECUTION]: The skill uses subprocess.run to execute git commands, python environment setups, and package installations. It also executes a verification script defined in install.yaml to confirm the environment is correctly configured.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data retrieved from the UI controls of target Windows applications.
  • Ingestion points: UI control text retrieved through the texts and qa_refresh_controls tools in SKILL.md.
  • Boundary markers: The instructions do not define specific delimiters or instructions to ignore potential commands embedded in application UI text.
  • Capability inventory: The skill has the ability to interact with the OS UI (click_input, set_edit_text), write reports to the filesystem (assets/test-case.md), and capture screenshots.
  • Sanitization: There is no explicit sanitization or filtering of the text content retrieved from the SUT (System Under Test) before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 08:52 AM
Security Audit — agent-trust-hub — windows-qa-engineer