gui-automation
Warn
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill allows the execution of arbitrary shell commands on the target environment.
- Evidence: The
cua do shellcommand inreferences/command-reference.mdprovides direct shell access. - [PRIVILEGE_ESCALATION]: The skill enables control over the local host machine's GUI and inputs.
- Evidence:
cua do-host-consentandcua do switch hostinSKILL.mdgrant permission to control the host. - [DATA_EXFILTRATION]: The skill can upload session recordings, including screenshots and terminal output, to a remote server.
- Evidence:
cua trajectory shareinSKILL.mduploads data tohttps://cua.ai. - [EXTERNAL_DOWNLOADS]: The skill recommends installing the vendor package
cuavia pip. - Evidence:
pip install cuainSKILL.md. - [INDIRECT_PROMPT_INJECTION]: The skill processes GUI content which may contain malicious instructions.
- Ingestion points:
cua do screenshotandcua do snapshotinSKILL.md. - Boundary markers: Absent.
- Capability inventory:
click,type,drag,shellexecution, andopen(file/URL) inreferences/command-reference.md. - Sanitization: Absent.
Audit Metadata