demo-with-narration

Pass

Audited by Gen Agent Trust Hub on Aug 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill requires the ability to capture screenshots of the desktop to verify that application windows have rendered correctly.
  • [PRIVILEGE_ESCALATION]: The skill uses desktop automation via System Events and accessibility APIs to interact with the GUI, including synthesizing keystrokes and clicks, which can be used to control other processes on the system.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and exercise external software artifacts (built binaries and running apps). This creates a surface where the agent might be influenced by untrusted output or behavior from these artifacts.
  • Ingestion points: External software artifacts and running applications (SKILL.md)
  • Boundary markers: Absent; there are no instructions to isolate or treat artifact output as untrusted
  • Capability inventory: Desktop automation (System Events), subshell execution, screenshot capture
  • Sanitization: Absent; the skill does not specify filtering or escaping of content generated by the artifacts being demoed
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 14, 2026, 05:49 PM
Security Audit — agent-trust-hub — demo-with-narration