fix-chrome-connection
Pass
Audited by Gen Agent Trust Hub on Apr 28, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [PROMPT_INJECTION]: The skill contains instructions that attempt to bypass human-in-the-loop safeguards. Phrases like "The user is not present to answer questions" and "Make reasonable choices autonomously" instruct the agent to operate without user oversight or confirmation.
- [COMMAND_EXECUTION]: The skill uses shell commands including
screencapture,sips,open, andosascriptto interact with the host operating system and control applications. - [DATA_EXFILTRATION]: The skill captures a full screenshot of the desktop using
screencaptureand requires the agent to read its contents. This constitutes data exposure, as any sensitive information visible on the user's screen, such as passwords, private messages, or confidential documents, is processed by the AI model.
Audit Metadata