cua-driver

Warn

Audited by Socket on Sep 24, 2026

1 alert found:

Anomaly
AnomalyLOW
README.md

The fragment is legitimate-looking installation and usage documentation for a GUI automation skill, with no direct evidence of malware in the text itself. The main security concern is the use of unpinned remote scripts executed directly by Bash or PowerShell, combined with broad accessibility, screen-recording, and browser-profile permissions. Inspect and verify installer contents, pin release hashes or commits, and limit permissions before use.

Confidence: 96%Severity: 62%
Audit Metadata
Analyzed At
Sep 24, 2026, 07:23 PM
Package URL
pkg:socket/skills-sh/dmmulroy%2F.dotfiles%2Fcua-driver%2F@198283d40eafdffb7b0c823e8d39421d2fcb8a1ece0efad904efca1db344d1d4
Security Audit — socket — cua-driver