windows-terminal

Warn

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill provides a pattern for runtime code generation and execution in SKILL.md. It instructs the agent to create temporary .bat files using fs.writeFileSync and execute them via execFileSync. This allows the execution of dynamically constructed scripts.
  • [COMMAND_EXECUTION]: The skill's primary purpose is to spawn system processes (wt.exe, cmd.exe, powershell.exe) with user-defined commands. This creates an attack surface for command execution on the host machine.
  • [PRIVILEGE_ESCALATION]: The skill documents a 'Hook Process Tree Escape' technique to bypass Windows Job Objects, allowing spawned terminal sessions to persist independently after the agent's process has terminated.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data through arguments like command and title. In combination with its file-writing and process-spawning capabilities, this creates a vulnerability surface where malicious input could trigger unauthorized system actions.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 25, 2026, 04:53 PM
Security Audit — agent-trust-hub — windows-terminal