focusAI

PassAudited by VirusTotal on May 14, 2026.

Findings (1)

The FocusAI skill implements a screen-monitoring and 'visual memory' system that captures screenshots and transmits them to cloud-based AI APIs (e.g., Qwen, Doubao) for analysis. While the SKILL.md documentation includes privacy disclaimers and instructions for the agent to seek user consent, the core functionality involves high-risk behaviors including automated screen recording, local shell execution (via start.bat), and data exfiltration to third-party providers. The skill directs the agent to facilitate the installation of external code from a GitHub repository (github.com/HR2AY/focusAI) and interact with a local HTTP API (127.0.0.1:8765), which could be abused for unauthorized surveillance or remote control if the underlying service is compromised.