windows-use

Warn

Audited by Socket on May 3, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/focus-and-send.cmd

No direct evidence of malware behavior like persistence, credential theft, or data exfiltration exists in this snippet. However, the script performs high-impact dual-use actions: it focuses a user-specified application window and injects arbitrary keystrokes into it. Additionally, embedding DELAY into a PowerShell -Command string without batch-layer validation increases the risk surface for unintended behavior if an attacker can control inputs, and the reliance on executables from a relative bin directory introduces integrity/supply-chain concerns. Overall: treat as suspicious-capable UI automation and require strict controls on who/what can invoke it and what arguments are allowed.

Confidence: 66%Severity: 60%
Audit Metadata
Analyzed At
May 3, 2026, 06:37 AM
Package URL
pkg:socket/skills-sh/NannaOlympicBroadcast%2FWindowsUseSkill%2Fwindows-use%2F@67faf5deca178cfc92725010c1b84fd3bb853a4c