gemini-computer-use
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill implements an autonomous agent loop that processes and interacts with arbitrary web content via Playwright. This introduces a surface for indirect prompt injection where instructions on a visited webpage could attempt to hijack the agent's behavior.
- Ingestion points: The agent navigates to arbitrary URLs and captures screenshots of pages in
scripts/computer_use_agent.py. - Capability inventory: The agent has the ability to click, type, scroll, and navigate within a browser session.
- Boundary markers: The implementation includes a safety confirmation mechanism (
prompt_for_safety_confirmation) that halts execution and requests user approval if the model flags an action as requiring confirmation. - Sanitization: The skill relies on the model's visual understanding of screenshots rather than raw HTML parsing, which provides some natural resistance, but does not provide explicit input filtering.
- [EXTERNAL_DOWNLOADS]: The skill requires the installation of external dependencies as documented in
SKILL.md, specifically thegoogle-genaiandplaywrightlibraries, as well as the Chromium browser engine viaplaywright install chromium. - [COMMAND_EXECUTION]: The
scripts/computer_use_agent.pyfile uses Playwright to perform browser actions. While limited to the browser context, these actions (clicking, typing, navigating) are driven by the LLM's interpretation of visual data, allowing for complex interactions with web applications.
Audit Metadata