autoskill
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it ingests untrusted data from the user's screen (OCR text and window titles) and uses it to generate new skill instructions. An attacker could display malicious text on the user's screen (e.g., via a website title) to manipulate the generated skill.
- Ingestion points:
fetch_window.pyretrieveswindow_titleandtextcontent from the localscreenpipeAPI. - Boundary markers: The LLM prompt in
synthesize.pylacks delimiters or negative constraints to prevent the model from obeying instructions embedded in the captured screen data. - Capability inventory:
run.pyhas the capability to write newSKILL.mdfiles to disk, andpromote.pycan move these files into the project's activeskills/directory where they become executable by the agent. - Sanitization:
redact.pysuccessfully removes PII and secrets but does not sanitize for instructional overrides or prompt injection payloads. - [DYNAMIC_EXECUTION]: The skill dynamically generates executable agent instructions (
SKILL.mdfiles) based on LLM synthesis of observed workflows. - The
run.pyscript writes drafted skills to a temporary proposal directory (~/.autoskill/proposed/). - The
promote.pyutility allows these generated instructions to be moved into the production skills path, facilitating the creation and future execution of code derived from untrusted inputs. - [DATA_EXFILTRATION]: The skill processes highly sensitive screen-capture data, creating a potential exposure surface.
- Mitigation: The skill implements significant privacy controls, including a default local-only architecture (LM Studio) and a
redact.pyutility that scrubs API keys, private keys, and emails before any data is sent to an LLM. - Mitigation:
backends.pyenforces acheck_remote_endpointpolicy that prevents sending screen-derived summaries over plaintext HTTP to remote hosts, requiring TLS for any non-loopback destinations.
Audit Metadata