computer-use-agents

Warn

Audited by Socket on Feb 27, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

This skill provides legitimate patterns and sample code for building 'computer use' AI agents (screen capture, model-driven actions, Docker sandboxing). There is no evidence of embedded backdoors, obfuscated payloads, or explicit malicious code in the provided fragments. However, the capability set (full-screen screenshots, keyboard/mouse control, shell execution, VNC access, and model API integration) is extremely powerful and dangerous if misused or deployed without strict isolation and auditing. The main risks are sensitive data exfiltration (screenshots sent to third-party models), unauthorized actions on the host (typing/clicking driven by model outputs), and network exposure via mapped ports. The documentation correctly emphasizes sandboxing, but the examples still expose attack surfaces (port mappings, temporary files). Treat this skill as high-risk: it is appropriate only in tightly controlled, isolated environments with explicit human approval, limited network egress, and careful auditing of what is sent to remote model APIs.

Confidence: 80%Severity: 65%
Audit Metadata
Analyzed At
Feb 27, 2026, 08:34 AM
Package URL
pkg:socket/skills-sh/sickn33%2Fantigravity-awesome-skills%2Fcomputer-use-agents%2F@d22459e16264ff68928a42a5e77139c7df4190db