linux-at-spi2
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill facilitates the automation of GUI applications via the AT-SPI2 protocol and D-Bus IPC. This includes the ability to perform UI actions and inject text input. However, the skill explicitly enforces strict security controls to mitigate misuse, including blocklists for sensitive applications (e.g., password managers like 'KeepassXC', terminal emulators, and authentication agents) and the use of permission tiers (read-only vs standard).
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from the Linux desktop environment by reading accessibility object properties such as names and text values. This creates an attack surface where a malicious application could display instructions that the agent might read and execute as commands.
- Ingestion points: Application names, roles, states, and text content accessed through the
Atspi.Accessibleinterface inSKILL.mdandreferences/advanced-patterns.md. - Boundary markers: Absent. The skill does not define specific delimiters or instructions for the agent to distinguish between UI-derived data and its core operating instructions.
- Capability inventory: The skill allows performing UI actions (
do_action), modifying application text (set_text), and monitoring system-wide accessibility events viaAtspi.EventListener. - Sanitization: The skill implements a
get_object_valuemethod that redacts text if the object's role isPASSWORD_TEXTor if its name contains sensitive keywords like 'password', 'secret', or 'token'.
Audit Metadata