remote-desktop-testing-linux

Warn

Audited by Socket on Jul 8, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/remote-desktop.mjs

No definitive evidence of intentional malware (no obvious keylogging, cryptomining, or exfiltration to unknown domains). However, the module has elevated risk patterns: it can execute user-provided commands inside the sandbox (expected for this tool but dangerous if input is not trusted), it writes screenshot output to an arbitrary host path provided by --output (possible host file clobbering), and it performs runtime npm installs into a local directory (supply-chain risk depending on registry integrity and version pinning). If this CLI is used only by trusted operators, the malware likelihood is low; if used with untrusted inputs, security risk increases substantially.

Confidence: 65%Severity: 55%
Audit Metadata
Analyzed At
Jul 8, 2026, 12:36 AM
Package URL
pkg:socket/skills-sh/letta-ai%2Fskills%2Fremote-desktop-testing-linux%2F@d3c1b1ce14d47b62c0b83f8735e9142c4029f422215c4680619c5650b15f7cdc
Security Audit — socket — remote-desktop-testing-linux