High-risk tools in Computer Use
11 of the 15 tools in Computer Use are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
execute_bashExecuteExecute a bash command on the virtual computer.
-
initialize_computerExecuteInitialize a virtual computer with the provided API key.
-
restart_computerExecuteRestart the virtual computer.
-
waitExecuteWait for the specified number of seconds.
-
double_clickExecutePerform a double click at the specified coordinates.
-
left_clickExecutePerform a left mouse click at the specified coordinates.
-
press_keyExecutePress a key or key combination (e.g., 'Enter', 'ctrl+c').
-
promptExecuteControl the computer with natural language using an AI agent.
-
right_clickExecutePerform a right mouse click at the specified coordinates.
-
scrollExecuteScroll in the specified direction and amount.
-
type_textExecuteType the specified text into the virtual computer.
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.