skills/trycua/cua/gui-automation/Gen Agent Trust Hub

gui-automation

Warn

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill allows the execution of arbitrary shell commands on the target environment.
  • Evidence: The cua do shell command in references/command-reference.md provides direct shell access.
  • [PRIVILEGE_ESCALATION]: The skill enables control over the local host machine's GUI and inputs.
  • Evidence: cua do-host-consent and cua do switch host in SKILL.md grant permission to control the host.
  • [DATA_EXFILTRATION]: The skill can upload session recordings, including screenshots and terminal output, to a remote server.
  • Evidence: cua trajectory share in SKILL.md uploads data to https://cua.ai.
  • [EXTERNAL_DOWNLOADS]: The skill recommends installing the vendor package cua via pip.
  • Evidence: pip install cua in SKILL.md.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes GUI content which may contain malicious instructions.
  • Ingestion points: cua do screenshot and cua do snapshot in SKILL.md.
  • Boundary markers: Absent.
  • Capability inventory: click, type, drag, shell execution, and open (file/URL) in references/command-reference.md.
  • Sanitization: Absent.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 17, 2026, 06:40 AM
Security Audit — agent-trust-hub — gui-automation