agent-desktop
Warn
Audited by Socket on Apr 7, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s desktop-control capabilities align with its stated purpose, but trust is weakened by the unverified `agent-desktop` native binary requirement and broad Accessibility permission. No clear credential harvesting or exfiltration is present, so this looks more like a high-risk host automation skill with supply-chain uncertainty than confirmed malware.
Confidence: 84%Severity: 72%
Audit Metadata