gemini-computer-use

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill implements an autonomous agent loop that processes and interacts with arbitrary web content via Playwright. This introduces a surface for indirect prompt injection where instructions on a visited webpage could attempt to hijack the agent's behavior.
  • Ingestion points: The agent navigates to arbitrary URLs and captures screenshots of pages in scripts/computer_use_agent.py.
  • Capability inventory: The agent has the ability to click, type, scroll, and navigate within a browser session.
  • Boundary markers: The implementation includes a safety confirmation mechanism (prompt_for_safety_confirmation) that halts execution and requests user approval if the model flags an action as requiring confirmation.
  • Sanitization: The skill relies on the model's visual understanding of screenshots rather than raw HTML parsing, which provides some natural resistance, but does not provide explicit input filtering.
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of external dependencies as documented in SKILL.md, specifically the google-genai and playwright libraries, as well as the Chromium browser engine via playwright install chromium.
  • [COMMAND_EXECUTION]: The scripts/computer_use_agent.py file uses Playwright to perform browser actions. While limited to the browser context, these actions (clicking, typing, navigating) are driven by the LLM's interpretation of visual data, allowing for complex interactions with web applications.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 03:41 AM
Security Audit — agent-trust-hub — gemini-computer-use