windows-qa-engineer
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill's installer (
scripts/skill_installer.py) fetches the Microsoft UFO framework from its official GitHub repository (https://github.com/microsoft/UFO.git) and installs necessary dependencies via pip. - [COMMAND_EXECUTION]: The skill uses
subprocess.runto execute git commands, python environment setups, and package installations. It also executes a verification script defined ininstall.yamlto confirm the environment is correctly configured. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data retrieved from the UI controls of target Windows applications.
- Ingestion points: UI control text retrieved through the
textsandqa_refresh_controlstools inSKILL.md. - Boundary markers: The instructions do not define specific delimiters or instructions to ignore potential commands embedded in application UI text.
- Capability inventory: The skill has the ability to interact with the OS UI (
click_input,set_edit_text), write reports to the filesystem (assets/test-case.md), and capture screenshots. - Sanitization: There is no explicit sanitization or filtering of the text content retrieved from the SUT (System Under Test) before it is processed by the agent.
Audit Metadata