peekaboo

Pass

Audited by Gen Agent Trust Hub on Jul 9, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill facilitates extensive interaction with the macOS operating system, including launching applications, managing windows, and simulating mouse and keyboard input. These capabilities are powerful but consistent with the primary objective of UI automation.
  • [EXTERNAL_DOWNLOADS]: The skill documentation and metadata reference the installation of the 'peekaboo' CLI tool via Homebrew from a third-party repository. This is a standard distribution method for macOS developer tools.
  • [INDIRECT_PROMPT_INJECTION]: The skill's core functionality involves capturing and analyzing the user's screen and UI elements. This creates a potential surface for indirect prompt injection, where malicious instructions present in an open application or on a webpage could influence the agent's behavior during automation tasks. There are no explicit instructions within the skill to sanitize or isolate UI content before processing it for instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 9, 2026, 10:45 PM
Security Audit — agent-trust-hub — peekaboo