desktop-computer-automation

Warn

Audited by Socket on Apr 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's behavior matches its stated purpose, and the install source appears to be the official Midscene package, so this is not malware-like deception. However, it is a high-impact automation skill that forwards model credentials and screenshot-derived desktop data to external AI endpoints while granting real mouse/keyboard control, making the security risk materially elevated even though purpose alignment is coherent.

Confidence: 87%Severity: 66%
Audit Metadata
Analyzed At
Apr 3, 2026, 04:45 PM
Package URL
pkg:socket/skills-sh/web-infra-dev%2Fmidscene-skills%2Fdesktop-computer-automation%2F@3388884679214ca9e3453033486ce41a830eff8b