Claw Use — Device Control for AI Agents
PassAudited by VirusTotal on May 11, 2026.
Findings (1)
The skill bundle provides instructions for an AI agent to use the 'cu' CLI tool for remote device control. While the functionality is transparently documented and aligned with its stated purpose, it introduces high-risk capabilities such as visual screen capture (cu screenshot), reading system notifications (cu notifications), and simulating user input or keystrokes (cu type, cu tap) on connected devices. These features represent a significant attack surface if the agent is manipulated, though no evidence of intentional malice, backdoors, or unauthorized data exfiltration was found in SKILL.md or _meta.json.
