linux-at-spi2

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill facilitates the automation of GUI applications via the AT-SPI2 protocol and D-Bus IPC. This includes the ability to perform UI actions and inject text input. However, the skill explicitly enforces strict security controls to mitigate misuse, including blocklists for sensitive applications (e.g., password managers like 'KeepassXC', terminal emulators, and authentication agents) and the use of permission tiers (read-only vs standard).
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from the Linux desktop environment by reading accessibility object properties such as names and text values. This creates an attack surface where a malicious application could display instructions that the agent might read and execute as commands.
  • Ingestion points: Application names, roles, states, and text content accessed through the Atspi.Accessible interface in SKILL.md and references/advanced-patterns.md.
  • Boundary markers: Absent. The skill does not define specific delimiters or instructions for the agent to distinguish between UI-derived data and its core operating instructions.
  • Capability inventory: The skill allows performing UI actions (do_action), modifying application text (set_text), and monitoring system-wide accessibility events via Atspi.EventListener.
  • Sanitization: The skill implements a get_object_value method that redacts text if the object's role is PASSWORD_TEXT or if its name contains sensitive keywords like 'password', 'secret', or 'token'.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 05:54 PM
Security Audit — agent-trust-hub — linux-at-spi2