agent-desktop

Warn

Audited by Socket on Apr 7, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s desktop-control capabilities align with its stated purpose, but trust is weakened by the unverified `agent-desktop` native binary requirement and broad Accessibility permission. No clear credential harvesting or exfiltration is present, so this looks more like a high-risk host automation skill with supply-chain uncertainty than confirmed malware.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Apr 7, 2026, 10:36 AM
Package URL
pkg:socket/skills-sh/superagent-ai%2Fgrok-cli%2Fagent-desktop%2F@3246f328f80f23623897577cb0382a3c3b791521
Security Audit — socket — agent-desktop