peekaboo
Pass
Audited by Gen Agent Trust Hub on Jun 26, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill installs the
peekaboobinary from a third-party Homebrew tap (steipete/tap/peekaboo), which is maintained by a well-known developer in the Apple community. - [COMMAND_EXECUTION]: Executes the
peekabooCLI to perform UI automation tasks including simulating mouse clicks, keyboard input, and window management. - [DATA_EXFILTRATION]: Provides capabilities to capture screen screenshots (
image,capture) and read the system clipboard (clipboard), which exposes potentially sensitive user data to the agent context. - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests untrusted visual data from the screen (
see,image --analyze) and has the capability to execute UI actions based on that data without explicit boundary markers or content sanitization. - [EXTERNAL_DOWNLOADS]: The documentation references an additional command-line utility
polterfor running builds, which is not included in the skill's official installation manifest.
Audit Metadata