fix-chrome-connection

Pass

Audited by Gen Agent Trust Hub on Apr 28, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: The skill contains instructions that attempt to bypass human-in-the-loop safeguards. Phrases like "The user is not present to answer questions" and "Make reasonable choices autonomously" instruct the agent to operate without user oversight or confirmation.
  • [COMMAND_EXECUTION]: The skill uses shell commands including screencapture, sips, open, and osascript to interact with the host operating system and control applications.
  • [DATA_EXFILTRATION]: The skill captures a full screenshot of the desktop using screencapture and requires the agent to read its contents. This constitutes data exposure, as any sensitive information visible on the user's screen, such as passwords, private messages, or confidential documents, is processed by the AI model.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 28, 2026, 01:39 PM
Security Audit — agent-trust-hub — fix-chrome-connection