game-automation

Warn

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: Simulation of User Input
  • The skill utilizes a PowerShell-based driver (WinDrive.ps1) to simulate low-level hardware events including mouse clicks, movement, keyboard typing, and holding keys.
  • Example: um win drive --proc Terraria "focus" "click 640 360" "key 0x1B" "type hello" "hold 0x44 1500".
  • While the documentation states that input is limited to the targeted game window, this is a soft constraint that could be bypassed if the agent targets other processes or if the foreground focus changes.
  • [COMMAND_EXECUTION]: Process Manipulation
  • The skill allows for listing all windowed processes and their PIDs (um win ps).
  • It provides the capability to terminate processes by their exact PID (um win kill <pid>).
  • [DATA_EXFILTRATION]: Windows Registry Access
  • The skill provides direct access to the Windows Registry through um win reg get.
  • Although the examples focus on game-specific settings (e.g., Unity or Unreal Engine configurations), the command can be used to query any key within the current user's registry hive (HKCU), which contains sensitive information, application settings, and system configurations.
  • [DATA_EXFILTRATION]: Screen and Buffer Capture
  • The um win shot command captures frames from specific process windows, even when covered by other windows (using Windows.Graphics.Capture).
  • The skill also suggests an "Agent Bridge" (AgentBridge.cs) that exposes in-game state and UI trees as JSON data over a local socket (127.0.0.1), which the agent then reads.
  • [INDIRECT_PROMPT_INJECTION]: Vulnerability to Malicious Data Ingestion
  • Ingestion points: The agent's decision loop relies on screenshots (um win shot), log file reading, and data from a JSON socket bridge.
  • Boundary markers: None mentioned; the agent is instructed to "decide" based on logs and visual data without clear delimiters or instruction filtering.
  • Capability inventory: The agent has the power to simulate input (mouse/keyboard), read/write registry values, and terminate system processes.
  • Sanitization: There is no evidence of sanitization for strings read from logs or UI trees before they are processed by the agent, potentially allowing a mod or game to inject instructions via on-screen text or log output.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Oct 1, 2026, 03:56 PM
Security Audit — agent-trust-hub — game-automation