notis-desktop-use

Pass

Audited by Gen Agent Trust Hub on Aug 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions to execute the peekaboo CLI tool on the local shell to perform desktop automation tasks, including clicking, typing, and managing windows.
  • [DATA_EXFILTRATION]: The skill captures sensitive visual data from the user's desktop, such as screenshots and UI accessibility trees. While it advises against exfiltrating data beyond the task's requirements, the capability to capture the live screen represents a significant exposure risk for private or confidential information.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it reads and processes untrusted data from the user's screen or application interfaces.
  • Ingestion points: Screen captures and UI maps ingested via peekaboo see and peekaboo image commands.
  • Boundary markers: Absent; the skill does not specify any delimiters or instructions for the agent to ignore content found within the captured UI.
  • Capability inventory: High-impact interaction capabilities including synthesized keyboard input (type, hotkey), mouse control (click), and process management (app launch/quit).
  • Sanitization: Absent; the skill provides no mechanism to sanitize or validate the content of the captured screen before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 14, 2026, 03:57 PM
Security Audit — agent-trust-hub — notis-desktop-use