computer-use-agents

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONPRIVILEGE_ESCALATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill implements a perception-action loop that ingests untrusted data from the screen, which could contain malicious instructions designed to influence the agent.
  • Ingestion points: Screen captures are generated via pyautogui.screenshot() in the capture_screenshot method within SKILL.md.
  • Boundary markers: The provided implementation logic does not include explicit delimiters or "ignore instructions" warnings within the perception loop.
  • Capability inventory: The skill grants the agent extensive system control, including mouse/keyboard automation (click, type, key, scroll) via pyautogui and shell command execution via the bash_20241022 tool.
  • Sanitization: No sanitization or validation is applied to data extracted from the visual feed before it is processed by the vision-language model.
  • [COMMAND_EXECUTION]: The skill utilizes shell commands to facilitate environment interactions and screen capture.
  • Evidence: subprocess.run(["scrot", "/tmp/screenshot.png"]) is used in the _handle_computer_action method to capture the screen state.
  • Intent: The usage is benign and follows standard desktop automation practices for Linux-based agent environments.
  • [PRIVILEGE_ESCALATION]: The skill contains templates for sandboxing that explicitly promote security best practices to prevent privilege escalation from the agent to the host.
  • Evidence: The Dockerfile implementation creates a non-root user (agent) and uses setcap -r to minimize capabilities. The docker-compose.yml configuration specifies no-new-privileges:true and a read_only root filesystem to minimize the blast radius of potential compromises.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:19 AM
Security Audit — agent-trust-hub — computer-use-agents