computer-use
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands using the
orcaCLI (or variantsorca-dev,orca-ide) to inspect and interact with the local operating system. It relies on the presence of these binaries in the environment to perform desktop automation. - [INDIRECT_PROMPT_INJECTION]: The skill processes data from untrusted sources by reading the UI state and accessibility trees of third-party applications (e.g., Slack, Spotify, browser windows). This content could contain malicious instructions designed to influence the agent's behavior.
- Ingestion points: accessibility trees, screenshots, and application state retrieved via
ORCA computer readorORCA computer list-apps. - Boundary markers: The current documentation stub does not specify delimiters or instructions for the agent to ignore embedded commands within the ingested UI data.
- Capability inventory: The agent has high-impact capabilities including clicking, typing, dragging, and setting values within the UI, which could be abused if an injection occurs.
- Sanitization: No sanitization or filtering of the retrieved UI content is described.
- [DATA_EXPOSURE]: The skill accesses sensitive system information by capturing screenshots and reading the accessibility trees of all active windows. This allows the agent to view potentially private information, including credentials or personal messages displayed on the user's screen.
Audit Metadata