automation-mcp

Pass

Audited by Gen Agent Trust Hub on Jul 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches the Bun runtime installation script from bun.sh, which is a well-known and recognized service.
  • [REMOTE_CODE_EXECUTION]: Setup involves executing the Bun installation script via a piped bash command; this is a standard installation pattern for the runtime.
  • [COMMAND_EXECUTION]: The skill provides tools for programmatic mouse and keyboard interaction, which is necessary for its stated desktop automation functionality.
  • [DATA_EXFILTRATION]: Through the screenshot tool, the agent can access visual data from the user's desktop environment to facilitate UI automation.
  • [PROMPT_INJECTION]: The skill presents a surface for indirect prompt injection via screen analysis. Ingestion points: screenshot tool in SKILL.md. Boundary markers: None. Capability inventory: Full control of system input via keyboard and mouse tools. Sanitization: None.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 15, 2026, 12:53 PM
Security Audit — agent-trust-hub — automation-mcp