autoskill

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it ingests untrusted data from the user's screen (OCR text and window titles) and uses it to generate new skill instructions. An attacker could display malicious text on the user's screen (e.g., via a website title) to manipulate the generated skill.
  • Ingestion points: fetch_window.py retrieves window_title and text content from the local screenpipe API.
  • Boundary markers: The LLM prompt in synthesize.py lacks delimiters or negative constraints to prevent the model from obeying instructions embedded in the captured screen data.
  • Capability inventory: run.py has the capability to write new SKILL.md files to disk, and promote.py can move these files into the project's active skills/ directory where they become executable by the agent.
  • Sanitization: redact.py successfully removes PII and secrets but does not sanitize for instructional overrides or prompt injection payloads.
  • [DYNAMIC_EXECUTION]: The skill dynamically generates executable agent instructions (SKILL.md files) based on LLM synthesis of observed workflows.
  • The run.py script writes drafted skills to a temporary proposal directory (~/.autoskill/proposed/).
  • The promote.py utility allows these generated instructions to be moved into the production skills path, facilitating the creation and future execution of code derived from untrusted inputs.
  • [DATA_EXFILTRATION]: The skill processes highly sensitive screen-capture data, creating a potential exposure surface.
  • Mitigation: The skill implements significant privacy controls, including a default local-only architecture (LM Studio) and a redact.py utility that scrubs API keys, private keys, and emails before any data is sent to an LLM.
  • Mitigation: backends.py enforces a check_remote_endpoint policy that prevents sending screen-derived summaries over plaintext HTTP to remote hosts, requiring TLS for any non-loopback destinations.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — autoskill