open-computer-use

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the 'open-computer-use' package globally using npm in references/installation.md. It also provides commands to install a remote skill from a GitHub repository using npx skills add iFurySt/open-codex-computer-use. While these are external dependencies, they are core to the skill's documented purpose and are presented transparently to the user.\n- [COMMAND_EXECUTION]: The skill provides numerous example commands for the open-computer-use (or ocu) CLI to perform desktop automation tasks. These include system checks (e.g., sw_vers), environment verification (doctor), and UI interaction tools (list_apps, get_app_state, click). All commands are intended for the local system to provide the 'Computer Use' capability.\n- [INDIRECT_PROMPT_INJECTION]: The skill documents a tool that ingests desktop UI content (accessibility trees and snapshots), which represents a surface for indirect prompt injection if a malicious application or webpage is active. The skill incorporates a robust 'Operating Rules' section in SKILL.md and a 'Safety' section in references/usage.md that act as mitigations. These instructions command the agent to treat the desktop as the user's session, avoid sensitive apps (e.g., password managers), and always pause for user confirmation before executing externally visible or destructive actions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 12:11 PM
Security Audit — agent-trust-hub — open-computer-use