computer-use-agents
Pass
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: SAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill implements a perception-action loop that uses
pyautoguito perform mouse and keyboard operations (clicking, typing, scrolling) directly on the operating system. - [REMOTE_CODE_EXECUTION]: The skill includes an implementation of the Anthropic
bashtool (BetaToolBash20241022), which allows an AI agent to execute arbitrary shell commands. This is an intended feature but represents a high-risk capability surface. - [PROMPT_INJECTION]: The skill is susceptible to Indirect Prompt Injection (Category 8) due to its architecture.
- Ingestion points: The agent ingests untrusted data through screen captures (
pyautogui.screenshot) and file reading (text_editortool). - Boundary markers: The provided snippets do not show explicit delimiters or warnings to the model to ignore instructions found within the screen content.
- Capability inventory: The skill provides the agent with GUI control (
pyautogui), shell access (bash), and file system modification capabilities. - Sanitization: No input sanitization or validation of screen content is present in the code examples.
- [SAFE]: The skill includes a 'Sandboxed Environment Pattern' that explicitly documents how to isolate the agent using Docker, non-root users, restricted network access, and Linux capability stripping to minimize the risk of host system compromise.
Audit Metadata