desktop-computer-automation
Warn
Audited by Socket on Apr 3, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill's behavior matches its stated purpose, and the install source appears to be the official Midscene package, so this is not malware-like deception. However, it is a high-impact automation skill that forwards model credentials and screenshot-derived desktop data to external AI endpoints while granting real mouse/keyboard control, making the security risk materially elevated even though purpose alignment is coherent.
Confidence: 87%Severity: 66%
Audit Metadata