agency-desktop-app-engineer
Pass
Audited by Gen Agent Trust Hub on Aug 11, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill architecture enforces strict security boundaries between untrusted renderer content and privileged system access, mandating features like context isolation and Chromium sandboxing.
- [SAFE]: Technical instructions provide secure code patterns for Inter-Process Communication (IPC), including mandatory input validation using Zod to prevent exploitation through malicious renderer inputs.
- [SAFE]: The release engineering section describes standard, secure practices for code signing and notarization using reputable services like DigiCert and Azure, with no evidence of secret exposure or insecure download patterns.
- [SAFE]: Analysis of the identity, mission, and rules reveals no prompt injection, data exfiltration, or obfuscation techniques.
Audit Metadata