game-automation
Warn
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: Simulation of User Input
- The skill utilizes a PowerShell-based driver (
WinDrive.ps1) to simulate low-level hardware events including mouse clicks, movement, keyboard typing, and holding keys. - Example:
um win drive --proc Terraria "focus" "click 640 360" "key 0x1B" "type hello" "hold 0x44 1500". - While the documentation states that input is limited to the targeted game window, this is a soft constraint that could be bypassed if the agent targets other processes or if the foreground focus changes.
- [COMMAND_EXECUTION]: Process Manipulation
- The skill allows for listing all windowed processes and their PIDs (
um win ps). - It provides the capability to terminate processes by their exact PID (
um win kill <pid>). - [DATA_EXFILTRATION]: Windows Registry Access
- The skill provides direct access to the Windows Registry through
um win reg get. - Although the examples focus on game-specific settings (e.g., Unity or Unreal Engine configurations), the command can be used to query any key within the current user's registry hive (
HKCU), which contains sensitive information, application settings, and system configurations. - [DATA_EXFILTRATION]: Screen and Buffer Capture
- The
um win shotcommand captures frames from specific process windows, even when covered by other windows (using Windows.Graphics.Capture). - The skill also suggests an "Agent Bridge" (
AgentBridge.cs) that exposes in-game state and UI trees as JSON data over a local socket (127.0.0.1), which the agent then reads. - [INDIRECT_PROMPT_INJECTION]: Vulnerability to Malicious Data Ingestion
- Ingestion points: The agent's decision loop relies on screenshots (
um win shot), log file reading, and data from a JSON socket bridge. - Boundary markers: None mentioned; the agent is instructed to "decide" based on logs and visual data without clear delimiters or instruction filtering.
- Capability inventory: The agent has the power to simulate input (mouse/keyboard), read/write registry values, and terminate system processes.
- Sanitization: There is no evidence of sanitization for strings read from logs or UI trees before they are processed by the agent, potentially allowing a mod or game to inject instructions via on-screen text or log output.
Audit Metadata