computer-use-agents
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONPRIVILEGE_ESCALATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill implements a perception-action loop that ingests untrusted data from the screen, which could contain malicious instructions designed to influence the agent.
- Ingestion points: Screen captures are generated via
pyautogui.screenshot()in thecapture_screenshotmethod withinSKILL.md. - Boundary markers: The provided implementation logic does not include explicit delimiters or "ignore instructions" warnings within the perception loop.
- Capability inventory: The skill grants the agent extensive system control, including mouse/keyboard automation (click, type, key, scroll) via
pyautoguiand shell command execution via thebash_20241022tool. - Sanitization: No sanitization or validation is applied to data extracted from the visual feed before it is processed by the vision-language model.
- [COMMAND_EXECUTION]: The skill utilizes shell commands to facilitate environment interactions and screen capture.
- Evidence:
subprocess.run(["scrot", "/tmp/screenshot.png"])is used in the_handle_computer_actionmethod to capture the screen state. - Intent: The usage is benign and follows standard desktop automation practices for Linux-based agent environments.
- [PRIVILEGE_ESCALATION]: The skill contains templates for sandboxing that explicitly promote security best practices to prevent privilege escalation from the agent to the host.
- Evidence: The
Dockerfileimplementation creates a non-root user (agent) and usessetcap -rto minimize capabilities. Thedocker-compose.ymlconfiguration specifiesno-new-privileges:trueand aread_onlyroot filesystem to minimize the blast radius of potential compromises.
Audit Metadata