OverviewHistoryStatsSecurity
Security
Independent checks from skills.sh's audit partners.
Independent checks from skills.sh's audit partners.
Fail5 providerslatest audit Apr 16, 2026
Independent checks from skills.sh's audit partners.
This skill provides templates for building AI agents capable of controlling a computer via GUI actions and shell commands. While it includes robust security advice and Docker-based sandboxing templates, the core functionality creates a significant attack surface for Indirect Prompt Injection. An agent using these patterns could be hijacked by malicious content displayed on a screen (e.g., a website or email), leading to unauthorized command execution within the agent's environment.
Detected behaviors
No alerts
No issues
1/1 file flagged
2 findings · Score: 80/100