cua-driver

Warn

Audited by Socket on Sep 2, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
SKILL.md

BENIGN. The skill’s capabilities align with its stated purpose of native GUI automation, and the main binary has credible same-org provenance. It is still a high-impact desktop automation skill with meaningful security risk from autonomous host actions and sensitive screen access, plus some installer trust concerns from raw script install paths, but there is no strong sign of credential harvesting, covert exfiltration, or malware.

Confidence: 87%Severity: 64%
SecurityMEDIUM
EMBEDDING.md

The fragment is not obviously malware by code-visible indicators (no network exfiltration, obfuscation, or credential theft shown), but it is a dual-use, high-privilege capability harness. It explicitly exercises and validates sensitive OS primitives: TCC responsibility-chain attribution checking, background Accessibility element tree retrieval, screenshot capture, and cursor movement via a local JSON-RPC daemon interface. As a supply-chain dependency, it carries elevated privacy/security risk primarily due to the nature of the capabilities and the explicit emphasis on prompt/attribution-chain behavior; further review of the full package is needed to rule out additional storage, transmission, or stealth/persistence beyond this fragment.

Confidence: 44%Severity: 78%
Audit Metadata
Analyzed At
Sep 2, 2026, 12:06 PM
Package URL
pkg:socket/skills-sh/qwenlm%2Fqwen-code%2Fcua-driver%2F@94c35042d157740d5016476b5b8adde2de8b5fd49d286f30507920db8a4da76a
Security Audit — socket — cua-driver