computer-use-mcp
Pass
Audited by Gen Agent Trust Hub on Aug 17, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it reads and processes data from external desktop applications.
- Ingestion points: The computer_get_app_state tool (SKILL.md) captures accessibility trees and semantic text from apps like the Helium browser.
- Boundary markers: The instructions do not define delimiters to separate system instructions from retrieved application data.
- Capability inventory: The agent can perform high-impact actions like computer_click, computer_set_value, computer_type_text, and computer_press_key.
- Sanitization: No data validation or sanitization of the UI state is mentioned.
Audit Metadata