Cua is open-core infrastructure for giving AI agents isolated computers, GUI control, cross-OS fleets, and evaluation environments through SDK, CLI, and MCP interfaces.
Direct verdict
Cua earns a pilot for engineering teams whose agents genuinely need native-computer access or cross-OS evaluation. Start with disposable, non-production machines and read-only tasks. Require an explicit permission policy, isolate identities and credentials, and promote write access only after failure-path results are acceptable.
What to verify
Run 250 tasks across two operating systems and five applications, including stale windows, ambiguous controls, hidden dialogs, denied permissions, prompt injection, network failure, duplicate submissions, and destructive actions. Measure verified completion, silent error, intervention, duplicate effects, policy bypass, recovery time, retained artifacts, and fully loaded cost per accepted task.