platynui

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill enables an agent to extract data from a desktop application's UI tree, which serves as a potential ingestion point for adversarial instructions embedded in element names or values. Ingestion points: The Get Attribute and Query keywords (referenced in SKILL.md and references/keywords-reference.md) allow the agent to read attributes such as Name, Text, and Value. Boundary markers: There are no explicit instructions or delimiters defined to guide the agent in ignoring instructions found within the UI data. Capability inventory: The skill grants capabilities to perform actions based on interpreted data, including Keyboard Type, Pointer Click, and Activate Window. Sanitization: No sanitization or validation logic is provided to filter UI content before it is processed by the agent.
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of dependencies from the Python Package Index (PyPI), a well-known package registry. Evidence: Instructions in SKILL.md and references/platform-setup.md guide users to install robotframework-PlatynUI, platynui-cli, and platynui-inspector using pip and uv tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 10:54 AM
Security Audit — agent-trust-hub — platynui