Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add bradthebeeble/mcp-macos-cua --skill cuagit clone --depth 1 https://github.com/bradthebeeble/mcp-macos-cuaWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/bradthebeeble/mcp-macos-cua/cua)<a href="https://agentmods.dev/skills/bradthebeeble/mcp-macos-cua/cua"><img src="https://agentmods.dev/badge/skills/bradthebeeble/mcp-macos-cua/cua/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/bradthebeeble/mcp-macos-cua/cua"><img src="https://agentmods.dev/badge/skills/bradthebeeble/mcp-macos-cua/cua.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00046 | $0.01105 |
| Opus 5 | $0.00023 | $0.00553 |
| Sonnet 5 | $0.00009 | $0.00221 |
| Haiku 4.5 | $0.00005 | $0.00111 |
Grade A, and why
cua scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 78 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Permission Bootstrap (run FIRST before anything else)
Before executing the user's instruction, check if CUA tools are pre-allowed so the user won't be prompted on every tool call.
- Read the file
.claude/settings.local.jsonin the current working directory (create.claude/dir if needed) - Check if ANY of these wildcards exist in
permissions.allowarray:"mcp__cua__*"OR"mcp__plugin_mcp-macos-cua_cua__*" - If NEITHER exists:
- Tell the user: "CUA tools require multiple permissions (screenshot, click, type, etc.). Would you like to allow all CUA tools at once so you won't be prompted for each action?"
- Also tell the user: "Note: macOS may prompt you to grant Accessibility and Screen Recording permissions to your terminal app (e.g. Terminal, iTerm, Warp). Go to System Settings > Privacy & Security > Accessibility (and Screen Recording) to enable them. You may need to restart your terminal after granting permissions."
- If the user approves (or doesn't object), add BOTH
"mcp__cua__*"and"mcp__plugin_mcp-macos-cua_cua__*"to thepermissions.allowarray in.claude/settings.local.json(preserve all existing entries). Both are needed to cover standalone and plugin-installed MCP server variants. - If the file doesn't exist, create it with:
{"permissions": {"allow": ["mcp__cua__*", "mcp__plugin_mcp-macos-cua_cua__*"]}}
- If at least one already exists, proceed silently
IMPORTANT: Do this check FIRST, before taking any screenshots or other actions.
You are now acting as a Computer Use Agent (CUA) on macOS. Your goal is to fulfill the user's instruction by interacting with the macOS GUI using the mcp__cua__* tools.
User Instruction
$ARGUMENTS
Available Tools
mcp__cua__screenshot- Take a screenshot (optionally of a specific app)mcp__cua__open_app- Open and activate an applicationmcp__cua__click- Click at screen coordinates (points, not pixels)mcp__cua__type_text- Type text into the frontmost appmcp__cua__key_press- Press keys/combos like "return", "cmd+c", "cmd+shift+a"mcp__cua__scroll- Scroll in any direction at current or given positionmcp__cua__get_ui_elements- Inspect accessibility tree of an app windowmcp__cua__click_ui_element- Click a named button/element via accessibilitymcp__cua__run_applescript- Run arbitrary AppleScript for complex automationmcp__cua__get_mouse_position- Get current mouse positionmcp__cua__move_mouse- Move mouse to coordinates
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago First seen · 78 lines · 46 tokens per session scan A 058c08afadb4
cua is a skill published in the GitHub repository bradthebeeble/mcp-macos-cua (0 stars, last pushed 4mo ago), licensed MIT. It adds 46 tokens to every session and 1,105 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
systematic-debugging
Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.
local-ai-agents
Build local-first AI agents that run entirely on a developer workstation with Microsoft Foundry Local and Qwen function-calling models. Covers Small Language Models (SLMs), the OpenAI-compatible local endpoint, sandboxed local tools, local RAG with Chroma, local MCP servers, hybrid cloud/local routing, and the…
next-cache-components-adoption
Turn on Cache Components in a Next.js app and resolve the blocking routes it surfaces. Use when the user wants to enable, adopt, or migrate to Cache Components, flip the cacheComponents flag, work through a flood of blocking-prerender / instant validation errors, run the cache-components-instant-false codemod, or…
chat-pet-sprite-creation
Use when creating or changing VS Code chat pet sprite art, sprite sheets, state animations, eye treatments, Stable/Insiders variants, or pet transitions under src/vs/workbench/contrib/chat/browser/widget/media/chatPet.
cpu-profile-analysis
Analyze V8/Chrome CPU profiles (.cpuprofile) and DevTools trace files (Trace-.json). Use when: profiling performance, investigating slow functions, comparing code paths, finding bottlenecks, analyzing timeToRequest, understanding call trees from sampling profiler data, analyzing layout/paint/rendering, investigating…
insight-error-page
Write or audit an insight-kind error page for the Next.js dev overlay. Use when creating a new errors/ .mdx page, auditing an existing one, or checking that a page matches the framework fix cards. Covers page structure, title alignment, FixCard cards with Copy prompt button, code snippets, terminology verification…