cua-driver
Warn
Audited by Socket on Sep 17, 2026
1 alert found:
AnomalyAnomalyREADME.md
LOWAnomalyLOW
README.md
The fragment is legitimate-looking installation and usage documentation for a GUI automation skill, with no direct evidence of malware in the text itself. The main security concern is the use of unpinned remote scripts executed directly by Bash or PowerShell, combined with broad accessibility, screen-recording, and browser-profile permissions. Inspect and verify installer contents, pin release hashes or commits, and limit permissions before use.
Confidence: 96%Severity: 62%
Audit Metadata