jev-desktop

Warn

Audited by Socket on Sep 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is internally coherent for remote-assisted desktop automation, and the external agent-desktop dependency appears same-project and publicly released rather than deceptive. The main risk is substantial data exposure: local screen contents and field values are transmitted to a remote API, and the tool can autonomously act inside desktop apps with real consequences despite having sensible confidence gates.

Confidence: 88%Severity: 68%
Audit Metadata
Analyzed At
Sep 19, 2026, 02:46 AM
Package URL
pkg:socket/skills-sh/lahfir%2Fagent-desktop%2Fjev-desktop%2F@4fa143016a263c822c368351c781c2bb246b306b02aca503afa43cd15f3e6fbb
Security Audit — socket — jev-desktop