Computer Use把AI从"告诉你怎么点"变成"它自己点"。这对没有API的老软件很有价值,也把风险从错误回答升级为真实操作。开发者最该关心的不是"它能识别多少按钮",而是每个动作能否被应用边界、操作类型和数据敏感度三重约束。
发布与可核验事实
GitHub在2026年10月1日宣布,Computer Use在GitHub Copilot CLI和GitHub Copilot应用中进入公共预览,覆盖macOS与Windows。它可读取辅助功能内容与视觉上下文,完成点击、输入、按键、滚动、拖拽和跨应用导航。官方定位是补足无API、无命令行界面、无模型上下文协议(MCP)集成的GUI工作流。
官方还明确:Copilot控制应用前会请求批准,用户可检查或重置"始终允许"的应用,组织管理设置可禁用该功能。在macOS上,还会引导用户开启辅助功能与屏幕录制权限。但"允许某个应用"只是第一层,并不能表达"允许幻灯片读取,但每次对外发送都要问"。
为什么要特别警惕"始终允许"?因为应用身份不等于业务意图。同一个浏览器既能读公开文档,也能打开邮箱、银行后台和密钥管理页。同一个文档应用既能编辑本地草稿,也能点击共享链接把内容发往外部。权限如果只细到应用级,便会把影响完全不同的动作压成一个开关。
技术原理:把观察、决策、执行拆开
一次桌面任务至少有三段:先从屏幕截图或辅助功能树得到观察,模型再选择目标与动作,最后操作层输入或点击。安全检查应在"决策已结构化,执行尚未发生"的窗口进行:先把应用标识、动作类型、目标文本、数据类型和是否对外发送交给策略器,再返回自动、询问或拒绝。
这个门禁必须位于模型之外。如果让同一个模型同时决定动作和判断"本次是否安全",恶意页面里的提示注入就可能同时污染两次决策。
最小权限还要考虑时间。用户批准"本次把数据填入幻灯片",不应自动变成一周内所有写入都允许。更稳妥的权限单元是"任务+应用+动作+目标范围+有效期"。任务结束、窗口内容变化或出现新收件人时,旧批准应自动失效。
#mermaid-svg-lWuZbtUlGmf1tpdd{font-family:"trebuchet ms",verdana,arial,sans-serif;font-size:16px;fill:#333;}@keyframes edge-animation-frame{from{stroke-dashoffset:0;}}@keyframes dash{to{stroke-dashoffset:0;}}#mermaid-svg-lWuZbtUlGmf1tpdd .edge-animation-slow{stroke-dasharray:9,5!important;stroke-dashoffset:900;animation:dash 50s linear infinite;stroke-linecap:round;}#mermaid-svg-lWuZbtUlGmf1tpdd .edge-animation-fast{stroke-dasharray:9,5!important;stroke-dashoffset:900;animation:dash 20s linear infinite;stroke-linecap:round;}#mermaid-svg-lWuZbtUlGmf1tpdd .error-icon{fill:#552222;}#mermaid-svg-lWuZbtUlGmf1tpdd .error-text{fill:#552222;stroke:#552222;}#mermaid-svg-lWuZbtUlGmf1tpdd .edge-thickness-normal{stroke-width:1px;}#mermaid-svg-lWuZbtUlGmf1tpdd .edge-thickness-thick{stroke-width:3.5px;}#mermaid-svg-lWuZbtUlGmf1tpdd .edge-pattern-solid{stroke-dasharray:0;}#mermaid-svg-lWuZbtUlGmf1tpdd .edge-thickness-invisible{stroke-width:0;fill:none;}#mermaid-svg-lWuZbtUlGmf1tpdd .edge-pattern-dashed{stroke-dasharray:3;}#mermaid-svg-lWuZbtUlGmf1tpdd .edge-pattern-dotted{stroke-dasharray:2;}#mermaid-svg-lWuZbtUlGmf1tpdd .marker{fill:#333333;stroke:#333333;}#mermaid-svg-lWuZbtUlGmf1tpdd .marker.cross{stroke:#333333;}#mermaid-svg-lWuZbtUlGmf1tpdd svg{font-family:"trebuchet ms",verdana,arial,sans-serif;font-size:16px;}#mermaid-svg-lWuZbtUlGmf1tpdd p{margin:0;}#mermaid-svg-lWuZbtUlGmf1tpdd .label{font-family:"trebuchet ms",verdana,arial,sans-serif;color:#333;}#mermaid-svg-lWuZbtUlGmf1tpdd .cluster-label text{fill:#333;}#mermaid-svg-lWuZbtUlGmf1tpdd .cluster-label span{color:#333;}#mermaid-svg-lWuZbtUlGmf1tpdd .cluster-label span p{background-color:transparent;}#mermaid-svg-lWuZbtUlGmf1tpdd .label text,#mermaid-svg-lWuZbtUlGmf1tpdd span{fill:#333;color:#333;}#mermaid-svg-lWuZbtUlGmf1tpdd .node rect,#mermaid-svg-lWuZbtUlGmf1tpdd .node circle,#mermaid-svg-lWuZbtUlGmf1tpdd .node ellipse,#mermaid-svg-lWuZbtUlGmf1tpdd .node polygon,#mermaid-svg-lWuZbtUlGmf1tpdd .node path{fill:#ECECFF;stroke:#9370DB;stroke-width:1px;}#mermaid-svg-lWuZbtUlGmf1tpdd .rough-node .label text,#mermaid-svg-lWuZbtUlGmf1tpdd .node .label text,#mermaid-svg-lWuZbtUlGmf1tpdd .image-shape .label,#mermaid-svg-lWuZbtUlGmf1tpdd .icon-shape .label{text-anchor:middle;}#mermaid-svg-lWuZbtUlGmf1tpdd .node .katex path{fill:#000;stroke:#000;stroke-width:1px;}#mermaid-svg-lWuZbtUlGmf1tpdd .rough-node .label,#mermaid-svg-lWuZbtUlGmf1tpdd .node .label,#mermaid-svg-lWuZbtUlGmf1tpdd .image-shape .label,#mermaid-svg-lWuZbtUlGmf1tpdd .icon-shape .label{text-align:center;}#mermaid-svg-lWuZbtUlGmf1tpdd .node.clickable{cursor:pointer;}#mermaid-svg-lWuZbtUlGmf1tpdd .root .anchor path{fill:#333333!important;stroke-width:0;stroke:#333333;}#mermaid-svg-lWuZbtUlGmf1tpdd .arrowheadPath{fill:#333333;}#mermaid-svg-lWuZbtUlGmf1tpdd .edgePath .path{stroke:#333333;stroke-width:2.0px;}#mermaid-svg-lWuZbtUlGmf1tpdd .flowchart-link{stroke:#333333;fill:none;}#mermaid-svg-lWuZbtUlGmf1tpdd .edgeLabel{background-color:rgba(232,232,232, 0.8);text-align:center;}#mermaid-svg-lWuZbtUlGmf1tpdd .edgeLabel p{background-color:rgba(232,232,232, 0.8);}#mermaid-svg-lWuZbtUlGmf1tpdd .edgeLabel rect{opacity:0.5;background-color:rgba(232,232,232, 0.8);fill:rgba(232,232,232, 0.8);}#mermaid-svg-lWuZbtUlGmf1tpdd .labelBkg{background-color:rgba(232, 232, 232, 0.5);}#mermaid-svg-lWuZbtUlGmf1tpdd .cluster rect{fill:#ffffde;stroke:#aaaa33;stroke-width:1px;}#mermaid-svg-lWuZbtUlGmf1tpdd .cluster text{fill:#333;}#mermaid-svg-lWuZbtUlGmf1tpdd .cluster span{color:#333;}#mermaid-svg-lWuZbtUlGmf1tpdd div.mermaidTooltip{position:absolute;text-align:center;max-width:200px;padding:2px;font-family:"trebuchet ms",verdana,arial,sans-serif;font-size:12px;background:hsl(80, 100%, 96.2745098039%);border:1px solid #aaaa33;border-radius:2px;pointer-events:none;z-index:100;}#mermaid-svg-lWuZbtUlGmf1tpdd .flowchartTitleText{text-anchor:middle;font-size:18px;fill:#333;}#mermaid-svg-lWuZbtUlGmf1tpdd rect.text{fill:none;stroke-width:0;}#mermaid-svg-lWuZbtUlGmf1tpdd .icon-shape,#mermaid-svg-lWuZbtUlGmf1tpdd .image-shape{background-color:rgba(232,232,232, 0.8);text-align:center;}#mermaid-svg-lWuZbtUlGmf1tpdd .icon-shape p,#mermaid-svg-lWuZbtUlGmf1tpdd .image-shape p{background-color:rgba(232,232,232, 0.8);padding:2px;}#mermaid-svg-lWuZbtUlGmf1tpdd .icon-shape .label rect,#mermaid-svg-lWuZbtUlGmf1tpdd .image-shape .label rect{opacity:0.5;background-color:rgba(232,232,232, 0.8);fill:rgba(232,232,232, 0.8);}#mermaid-svg-lWuZbtUlGmf1tpdd .label-icon{display:inline-block;height:1em;overflow:visible;vertical-align:-0.125em;}#mermaid-svg-lWuZbtUlGmf1tpdd .node .label-icon path{fill:currentColor;stroke:revert;stroke-width:revert;}#mermaid-svg-lWuZbtUlGmf1tpdd :root{--mermaid-font-family:"trebuchet ms",verdana,arial,sans-serif;} 自动
询问
拒绝
截图或辅助功能树
Agent提出结构化动作
校验应用身份
判断读写与对外发送
检测敏感数据
策略结果
执行并记录
用户确认后执行
终止与报告
最小实践:三维动作门禁
依赖安装:无。保存为desktop_gate.py,运行python3 desktop_gate.py。
python
POLICY = {
"browser": {"read": "auto", "write": "ask"},
"slides": {"read": "auto", "write": "ask"},
"password_manager": {"read": "deny", "write": "deny"},
}
def decide(app, action, contains_sensitive=False):
if contains_sensitive:
return "deny"
return POLICY.get(app, {}).get(action, "deny")
cases = [
("browser", "read", False),
("slides", "write", False),
("password_manager", "read", False),
("browser", "write", True),
]
result = [decide(*case) for case in cases]
print(result)
assert result == ["auto", "ask", "deny", "deny"]
默认策略是"不在白名单就拒绝";写入需要询问,密码管理器和敏感数据直接拒绝。本文示例已用Python 3.9.6在本次任务中实际运行,四个结果与断言一致。未安装或开启GitHub Copilot Computer Use,没有对真实桌面进行自动操作。
具体场景:报销录入
假设Agent从浏览器读取报销单,再将金额输入老式财务客户端。"读取公开说明"可自动,"读取个人银行账户"应拒绝,"填入草稿"可询问,"最终提交"则应在界面上显示金额、收款方和附件摘要,让用户确认。不要用一个"允许财务应用"开关替代整个风险模型。
还要处理"界面在确认后变了"的检查时机攻击。用户看到的是A账户与100元,Agent实际点击时,页面可能已切换为B账户或1000元。高风险执行前应重新读取关键字段,与批准摘要比较;不一致就立即停止,而不是试图自行推断哪个值更"像是对的"。
边界、误区与行动清单
视觉识别会因窗口遮挡、缩放、动画和界面更新而失效;辅助功能树也可能缺标签。因此执行前要重新读取目标,执行后要验证结果,而不是凭坐标假设成功。永久允许不应覆盖凭据读取、文件删除、付款、发布、外发信息和安全设置变更。组织管理员还要设置应用允许列表、日志保留和紧急停止方法。
日志本身也要最小化。保留任务ID、应用标识、动作类型、策略结果、批准人和执行回执,不代表要存下全屏截图、密码框内容或整份客户文档。敏感观察可用摘要、字段标签或受控存储代替,并设定短保留期。否则为了审计Agent,反而新建了一个高价值数据泄漏面。
我的判断是,Computer Use不会取代API,它是为没有结构化接口的最后一公里补位。能调API的任务仍应优先使用可校验参数、权限范围和错误码的接口。GUI自动化的价值是覆盖空白,不是把所有系统退回模糊的视觉点击。
一个安全的试点方法是:先选只读、可重现、无个人数据的流程,记录目标识别错误、人工打断和完成率;然后再开放本地草稿写入;最后才考虑对外发送。每扩大一层权限,都应有新的验收门槛,不是沿用上一层的成功率。
如果只能先禁止一类桌面操作,你会选凭据读取、对外发送、付款,还是文件删除?
关注「蜗牛聊AI」,一起看懂技术变化背后的真正机会。
本文首发于 java4u.cn,转载请注明出处。