computer-use-agents
Pass
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides implementation templates for comprehensive system interaction, including mouse, keyboard, and shell control. Code in
SKILL.mdusespyautoguifor desktop automation and defines abashtool via the Anthropic SDK, which allows the agent to execute arbitrary shell commands. - [DATA_EXFILTRATION]: The skill's architecture involves capturing full desktop screenshots for AI processing. The
capture_screenshotmethod and the use of thescrotutility viasubprocess.runinSKILL.mdextract the visual state of the machine, which is then encoded and transmitted to an external vision-language model. Users should be aware that sensitive information visible on the screen will be shared with the model provider. - [PROMPT_INJECTION]: The vision-based perception loop creates a surface for indirect prompt injection by ingesting untrusted screen content. 1. Ingestion points: Desktop screenshots captured via
pyautoguiandscrotinSKILL.md. 2. Boundary markers: The provided code snippets do not include explicit prompt delimiters or instructions for the agent to ignore adversarial text found within captured images. 3. Capability inventory: The agent has high-privilege capabilities including UI control (pyautogui), shell access (bashtool), and file modification (text_editortool). 4. Sanitization: There is no implemented visual filtering or instruction-stripping logic to sanitize screen data before it is analyzed by the model.
Audit Metadata