remote-agents
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill downloads developer toolchains (Visual Studio, Git, Python, PowerShell, 7-Zip) from official, trusted domains such as aka.ms, github.com, and python.org. These downloads are verified using Get-AuthenticodeSignature and SHA-256 hash checks in scripts/bootstrap-windows.ps1 and scripts/install-7zip.ps1, ensuring the integrity of the remote code. Findings are documented as safe due to the use of trusted sources and integrity verification.
- [COMMAND_EXECUTION]: Multiple scripts (scripts/desktop.py, scripts/host.sh, scripts/onboard.py) utilize subprocess and PowerShell to manage remote host lifecycle, RDP sessions, and the WireGuard bridge. These operations are essential for the skill's functionality and are implemented with security considerations such as utilizing SSH-over-SSM for transport and resolving paths securely.
- [OBFUSCATION]: scripts/desktop.py and scripts/onboard.py use Base64 encoding to pass scripts to PowerShell's -EncodedCommand parameter. This is a common and legitimate technique in Windows automation to ensure script blocks are transmitted correctly through shells and is not an attempt to hide malicious intent.
- [PRIVILEGE_ESCALATION]: The skill performs administrative tasks such as modifying firewall rules, registry settings, and installing system services. scripts/install-work-bridge-service.py adds specific sudoers entries to allow passwordless control of the bridge service. These escalations are limited in scope to the necessary management of the remote agent environment.
- [PERSISTENCE]: To maintain the remote environment, the skill installs launchd daemons (macOS), systemd units (Linux), and registers Windows Scheduled Tasks for GUI interaction. These persistence mechanisms are transparently documented as part of the bridge and desktop features.
- [INDIRECT_PROMPT_INJECTION]: The skill includes functionality for agents to process external prompt files (scripts/run-visual-qa.py). The risk of indirect injection is addressed through explicit warnings in the security documentation (references/security.md) and the use of instruction preambles to guide agent behavior when launching GUI processes. Findings are low severity.
Audit Metadata