pty-capture

Warn

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: MEDIUMPRIVILEGE_ESCALATIONDYNAMIC_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PRIVILEGE_ESCALATION]: The skill instructs the agent to perform administrative actions to configure the capture environment.
  • Evidence: Use of sudo apt-get install -y cage wtype in platforms/linux.md for package installation.
  • Evidence: Use of powershell -ExecutionPolicy Bypass in platforms/windows.md to execute local scripts.
  • [DYNAMIC_EXECUTION]: The skill executes dynamically constructed scripts to interface with low-level terminal APIs.
  • Evidence: A Perl one-liner used for raw PTY capture in platforms/linux.md (perl -e '$|=1; while(sysread(STDIN,$b,1)){printf "%02x ",ord($b)}').
  • Evidence: An inline Python script executed via SSH in platforms/macos.md that uses tty and termios modules to set raw mode and dump bytes.
  • [COMMAND_EXECUTION]: The skill invokes various system utilities and internal scripts to control virtualized environments and capture state.
  • Evidence: Execution of ${DROID_PLUGIN_ROOT}/bin/tctl and platform-specific control scripts (mac-ctl.sh, vm-ctl.sh) for snapshots, keystroke injection, and VM management.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input sequences from terminal emulators which could theoretically contain malicious instructions if the captured data is used in downstream decision-making.
  • Ingestion points: STDIN buffer read in platforms/linux.md, platforms/macos.md, and Windows capture scripts.
  • Boundary markers: Absent; the skill reads raw bytes directly from the terminal input stream.
  • Capability inventory: Shell command execution, dynamic script execution, and file system writes for snapshots.
  • Sanitization: Absent; input is treated as raw data and converted to hex pairs.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 16, 2026, 04:38 PM