open-computer-use-automation

Warn

Audited by Socket on May 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill's capabilities mostly match its stated desktop-automation purpose, and the npm install path is plausible, but it grants very broad local control and sensitive screen access. The biggest concern is the transitive `npx skills add` installation path to a third-party repo, which extends trust beyond the core CLI. This looks more like a high-risk automation skill than confirmed malware.

Confidence: 84%Severity: 74%
Audit Metadata
Analyzed At
May 18, 2026, 12:11 AM
Package URL
pkg:socket/skills-sh/aradotso%2Fcodex-skills%2Fopen-computer-use-automation%2F@1c452453284011d3a6be9521adffd340ffb5d4a8