selkies-desktop-layer

Pass

Audited by Gen Agent Trust Hub on Jun 20, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill establishes an environment where a web browser (Chrome) and desktop automation tools (wtype, wlrctl, xdotool, ydotool) coexist, creating a surface for indirect prompt injection. Content from external websites could potentially influence the agent's use of these tools. 1. Ingestion points: Google Chrome browser (mentioned in SKILL.md). 2. Boundary markers: Absent; no specific delimiters or warnings for browser-sourced content are defined. 3. Capability inventory: Screen capture (wl-screenshot-pixelflux), input simulation (wtype, wlrctl, ydotool), window management (wlrctl toplevel), and clipboard access (wl-clipboard). 4. Sanitization: Absent; the skill does not define filters for content ingested via the browser.
  • [COMMAND_EXECUTION]: The skill includes and configures various desktop automation tools for input simulation and window management, such as wtype, wlrctl, xdotool, and ydotool. These are used for 'charly check wl' automation and pointer clicks via the Chrome DevTools Protocol. Specifically, ydotool is noted as requiring access to /dev/uinput for input injection operations.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 20, 2026, 04:50 AM