bezalel-computer
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill includes a
computer__bashtool which allows for the execution of arbitrary shell commands on the host desktop. The documentation explicitly clarifies that these commands are not sandboxed and run with the privileges of the desktop user. - [REMOTE_CODE_EXECUTION]: The skill facilitates remote code execution by design, permitting the installation of external software through system package managers and language-specific registries like npm and pip.
- [EXTERNAL_DOWNLOADS]: The skill is intended to interact with external sources for package installation and web browsing. While these represent a source of external code, they are standard administrative functions for a desktop control skill.
- [INDIRECT_PROMPT_INJECTION]: The skill possesses a significant attack surface for indirect prompt injection because it ingests untrusted data from the desktop screen and local files without explicit sanitization or boundary markers. 1. Ingestion points: The vision-based
computer__tasktool and shell-based file reading tools provide pathways for external data into the agent's context. 2. Boundary markers: The instructions do not specify any delimiters or ignore-instructions markers for data retrieved from the desktop. 3. Capability inventory: The agent has the ability to execute high-privilege shell commands and manage system lifecycle states. 4. Sanitization: There is no requirement in the instructions to validate or filter commands embedded in the data processed by the vision loop or shell.
Audit Metadata