desktop-control

Warn

Audited by Socket on Jun 14, 2026

1 alert found:

Anomaly
AnomalyLOW
platforms/macos.md

The provided content is macOS documentation for a high-privilege UI automation driver that can enumerate windows (including background/off-space and security/modal contexts), inject keystrokes/hotkeys into targeted apps via Accessibility, and optionally capture the screen via ScreenCaptureKit—each gated by TCC. The fragment contains no direct malware indicators (no exfiltration/persistence/obfuscated payloads shown), but the described capabilities are inherently spyware-adjacent and represent a significant security risk if misused or if upstream implementation adds network transmission or covert storage of captured content.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 14, 2026, 08:41 AM
Package URL
pkg:socket/skills-sh/factory-ai%2Ffactory-plugins%2Fdesktop-control%2F@15bf68ba9c80ef32642591bbf217bdb01f070cd5cd475e264a3d290cc616d5d4
Security Audit — socket — desktop-control