cua-driver
Audited by Socket on Sep 2, 2026
2 alerts found:
AnomalySecurityBENIGN. The skill’s capabilities align with its stated purpose of native GUI automation, and the main binary has credible same-org provenance. It is still a high-impact desktop automation skill with meaningful security risk from autonomous host actions and sensitive screen access, plus some installer trust concerns from raw script install paths, but there is no strong sign of credential harvesting, covert exfiltration, or malware.
The fragment is not obviously malware by code-visible indicators (no network exfiltration, obfuscation, or credential theft shown), but it is a dual-use, high-privilege capability harness. It explicitly exercises and validates sensitive OS primitives: TCC responsibility-chain attribution checking, background Accessibility element tree retrieval, screenshot capture, and cursor movement via a local JSON-RPC daemon interface. As a supply-chain dependency, it carries elevated privacy/security risk primarily due to the nature of the capabilities and the explicit emphasis on prompt/attribution-chain behavior; further review of the full package is needed to rule out additional storage, transmission, or stealth/persistence beyond this fragment.