computer-use-agents

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides implementation templates for comprehensive system interaction, including mouse, keyboard, and shell control. Code in SKILL.md uses pyautogui for desktop automation and defines a bash tool via the Anthropic SDK, which allows the agent to execute arbitrary shell commands.
  • [DATA_EXFILTRATION]: The skill's architecture involves capturing full desktop screenshots for AI processing. The capture_screenshot method and the use of the scrot utility via subprocess.run in SKILL.md extract the visual state of the machine, which is then encoded and transmitted to an external vision-language model. Users should be aware that sensitive information visible on the screen will be shared with the model provider.
  • [PROMPT_INJECTION]: The vision-based perception loop creates a surface for indirect prompt injection by ingesting untrusted screen content. 1. Ingestion points: Desktop screenshots captured via pyautogui and scrot in SKILL.md. 2. Boundary markers: The provided code snippets do not include explicit prompt delimiters or instructions for the agent to ignore adversarial text found within captured images. 3. Capability inventory: The agent has high-privilege capabilities including UI control (pyautogui), shell access (bash tool), and file modification (text_editor tool). 4. Sanitization: There is no implemented visual filtering or instruction-stripping logic to sanitize screen data before it is analyzed by the model.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 05:45 AM
Security Audit — agent-trust-hub — computer-use-agents