computer-use-agents

Warn

Audited by Socket on May 12, 2026

1 alert found:

Anomaly
AnomalyLOW
sub-skills/perception-reasoning-action-loop.md

No definitive malware behavior (e.g., credential theft, persistence, hidden payloads, explicit exfiltration destinations) is visible in the provided fragment alone. However, it is a high-impact dual-use component: it captures full-screen contents (privacy/secret exposure risk) and executes arbitrary mouse/keyboard actions from an unvalidated action dict (risk of unintended or malicious UI operations). Because the snippet is truncated and omits the model/API request/response handling, the likelihood of screenshot transmission and any safety controls cannot be fully verified from this fragment.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
May 12, 2026, 01:46 PM
Package URL
pkg:socket/skills-sh/Dokhacgiakhoa%2Fantigravity-ide%2Fcomputer-use-agents%2F@68400b8e442e11ab6147928f622a25aa5e4a6d7c
Security Audit — socket — computer-use-agents