windows-desktop-e2e

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the subprocess module to execute the application being tested and utility tools like ffmpeg.\n
  • subprocess.Popen is used in conftest.py to launch the target .exe within an isolated environment.\n
  • ffmpeg is invoked via subprocess.Popen to perform screen recording for test artifacts.\n- [EXTERNAL_DOWNLOADS]: The instructions include steps to install dependencies from well-known registries and official sources.\n
  • Python packages are installed via pip from the standard PyPI registry.\n
  • The Windows Sandbox configuration utilizes winget to install Python from Microsoft's official repository.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external sources, such as UI element properties and environment variables, which represents a potential attack surface.\n
  • Ingestion points: The skill reads application titles, control IDs (AutomationId), and environment-provided file paths.\n
  • Capability inventory: The skill has the ability to start/kill processes and write files to the local system.\n
  • Sanitization: Input arguments are processed using shlex.split to mitigate common command injection risks.\n
  • Boundary markers: None specifically defined for LLM context separation.\n- [DYNAMIC_EXECUTION]: The skill uses ctypes to interface with the Windows kernel API for process management.\n
  • It utilizes kernel32.dll to create Job Objects, ensuring that child processes are terminated correctly when tests finish.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 02:39 AM
Security Audit — agent-trust-hub — windows-desktop-e2e