cua-driver

Warn

Audited by Socket on Sep 17, 2026

1 alert found:

Anomaly
AnomalyLOW
README.md

The fragment is legitimate-looking installation and usage documentation for a GUI automation skill, with no direct evidence of malware in the text itself. The main security concern is the use of unpinned remote scripts executed directly by Bash or PowerShell, combined with broad accessibility, screen-recording, and browser-profile permissions. Inspect and verify installer contents, pin release hashes or commits, and limit permissions before use.

Confidence: 96%Severity: 62%
Audit Metadata
Analyzed At
Sep 17, 2026, 11:42 PM
Package URL
pkg:socket/skills-sh/trycua%2Fcua%2Fcua-driver%2F@d175d186e147b636b4810e8d131f6122ceeccdfd512ce299f586175b4c91840a
Security Audit — socket — cua-driver