windows-desktop-e2e

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill configuration for Windows Sandbox (e2e-sandbox.wsb) specifies downloading the Python interpreter using winget, which is a standard package manager for Windows provided by Microsoft.\n- [DYNAMIC_EXECUTION]: The skill uses the ctypes library to access Windows system functions (kernel32.dll) for process management. Specifically, it uses Job Objects to ensure that the application under test and any child processes are correctly terminated after testing, which is a defensive coding practice.\n- [COMMAND_EXECUTION]: The skill uses subprocess.Popen to launch the application under test and the ffmpeg utility for screen recording. These actions are triggered based on local environment variables and are standard for GUI automation workflows.\n- [INDIRECT_PROMPT_INJECTION]: The skill interacts with UI elements that may display untrusted content from the application being tested.\n * Ingestion points: The skill reads element properties like title and window_text via pywinauto in pages/base_page.py.\n * Boundary markers: Interaction is limited to specific UIA selectors, separating UI content from the automation control logic.\n * Capability inventory: Capabilities include launching processes (subprocess.Popen), terminating processes (proc.kill), and writing files to a local artifacts/ directory.\n * Sanitization: The type_text and _trace methods include logic to redact sensitive text from logs by default, reducing the risk of accidental data exposure.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:40 PM
Security Audit — agent-trust-hub — windows-desktop-e2e