windows-desktop-e2e
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill configuration for Windows Sandbox (
e2e-sandbox.wsb) specifies downloading the Python interpreter usingwinget, which is a standard package manager for Windows provided by Microsoft.\n- [DYNAMIC_EXECUTION]: The skill uses thectypeslibrary to access Windows system functions (kernel32.dll) for process management. Specifically, it uses Job Objects to ensure that the application under test and any child processes are correctly terminated after testing, which is a defensive coding practice.\n- [COMMAND_EXECUTION]: The skill usessubprocess.Popento launch the application under test and theffmpegutility for screen recording. These actions are triggered based on local environment variables and are standard for GUI automation workflows.\n- [INDIRECT_PROMPT_INJECTION]: The skill interacts with UI elements that may display untrusted content from the application being tested.\n * Ingestion points: The skill reads element properties liketitleandwindow_textviapywinautoinpages/base_page.py.\n * Boundary markers: Interaction is limited to specific UIA selectors, separating UI content from the automation control logic.\n * Capability inventory: Capabilities include launching processes (subprocess.Popen), terminating processes (proc.kill), and writing files to a localartifacts/directory.\n * Sanitization: Thetype_textand_tracemethods include logic to redact sensitive text from logs by default, reducing the risk of accidental data exposure.
Audit Metadata