computer-use-agents

Pass

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: SAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill implements a perception-action loop that uses pyautogui to perform mouse and keyboard operations (clicking, typing, scrolling) directly on the operating system.
  • [REMOTE_CODE_EXECUTION]: The skill includes an implementation of the Anthropic bash tool (BetaToolBash20241022), which allows an AI agent to execute arbitrary shell commands. This is an intended feature but represents a high-risk capability surface.
  • [PROMPT_INJECTION]: The skill is susceptible to Indirect Prompt Injection (Category 8) due to its architecture.
  • Ingestion points: The agent ingests untrusted data through screen captures (pyautogui.screenshot) and file reading (text_editor tool).
  • Boundary markers: The provided snippets do not show explicit delimiters or warnings to the model to ignore instructions found within the screen content.
  • Capability inventory: The skill provides the agent with GUI control (pyautogui), shell access (bash), and file system modification capabilities.
  • Sanitization: No input sanitization or validation of screen content is present in the code examples.
  • [SAFE]: The skill includes a 'Sandboxed Environment Pattern' that explicitly documents how to isolate the agent using Docker, non-root users, restricted network access, and Linux capability stripping to minimize the risk of host system compromise.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 11, 2026, 06:18 PM
Security Audit — agent-trust-hub — computer-use-agents