Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/oneworks-ai/app/cua-drivernpx skills add oneworks-ai/app --skill cua-drivergit clone --depth 1 https://github.com/oneworks-ai/appWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/oneworks-ai/app/cua-driver)<a href="https://agentmods.dev/skills/oneworks-ai/app/cua-driver"><img src="https://agentmods.dev/badge/skills/oneworks-ai/app/cua-driver.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00050 | $0.01044 |
| Opus 5 | $0.00025 | $0.00522 |
| Sonnet 5 | $0.00010 | $0.00209 |
| Haiku 4.5 | $0.00005 | $0.00104 |
Grade A, and why
cua-driver scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 47 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Computer Control - CUA
Use the Cua Driver MCP tools contributed by this plugin. OneWorks owns the session and agent loop; the plugin runtime owns driver installation, daemon startup, permission preflight, and the long-lived MCP transport.
User Contract
The user only describes the desired macOS outcome. Do not ask them to run setup commands, start a daemon, resolve a binary, or check permissions. Do not expose those prerequisites as task steps. If macOS requires a new Accessibility or Screen Recording grant, explain the specific system permission and retry the original action after it is granted.
Keep the user's frontmost app frontmost. Use Cua Driver tools whenever an action touches native GUI state. Do not substitute open, mutating AppleScript, cliclick, raw desktop screenshots, or foregrounding shortcuts; those paths can activate apps, move the real cursor, switch Spaces, or bypass the driver's evidence trail.
The plugin runtime automatically prepares a visible virtual Agent pointer before exposing the tools. The physical mouse remains untouched. Each session receives its own stable automatic color. Every workflow starts its pointer from the main-display center unless cursor_start is provided. If the user requests a particular color, pass cursor_color; if they request a particular starting point, pass logical main-display coordinates through cursor_start. For low-level recovery calls, use set_session_cursor_color or set_session_cursor_start once before the next pointer action. Do not add daemon setup commands, raw cursor-style operations, or arbitrary pointer-motion steps to the task.
Action Protocol
Prefer execute_workflow whenever one app has two or more actions known in advance. When independent work is ready for multiple apps, submit it once with execute_workflows; different app resources may advance concurrently, workflows touching the same app remain serial, and pointer actions retain the global safety lock. Use resume_workflow only after a returned agent/user checkpoint. Use get_workflow_step_results only when the compact result does not contain enough detail. Read WORKFLOWS.md before composing a workflow.
What ships with it
3 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 47 lines · 50 tokens per session scan A a5ff729555d9
cua-driver is a skill published in the GitHub repository oneworks-ai/app (18 stars, last pushed 4d ago), licensed MIT. It adds 50 tokens to every session and 1,044 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
neo4j-modeling-skill
Design, review, and refactor Neo4j graph data models. Use when choosing node labels vs relationship types vs properties, migrating relational/document schemas to graph, detecting anti-patterns (generic labels, supernodes, missing constraints), designing intermediate nodes for n-ary relationships, enforcing schema with…
alphafold-database
Access AlphaFold 200M+ AI-predicted protein structures. Retrieve structures by UniProt ID, download PDB/mmCIF files, analyze confidence metrics (pLDDT, PAE), for drug discovery and structural biology.
lov-env-management
统一管理平台、账号与多组 API Key,维护有效期和启用状态,安全同步到 zsh 或用户会话环境,并提供脱敏 Dashboard;用户说“管理环境变量”“rotate API keys”时使用。.
lov-deploy-to-vercel
Deploy frontend projects to Vercel with automatic custom domain setup. Handles Vite, Next.js, CRA, and static sites. Auto-configures Cloudflare DNS CNAME records and Vercel domain aliases. Supports SPA routing via vercel.json. Trigger when user says "deploy to vercel", "部署到 vercel", "vercel deploy", or mentions a…
lov-bp-outline
Turn existing project materials into a source-backed investor BP brief, evidence ledger, and 12–15 slide outline. Use before making slides, when the product positioning is unclear, or when an existing outline is too technical, generic, or unsupported. Trigger on "写 BP 大纲", "融资叙事", "梳理商业计划书", "先不要做 PPT", "BP outline"…
github-create-pr
Create GitHub pull requests from a local branch using a reviewable workflow for branch checks, diff analysis, PR title/body writing, and gh CLI creation. Use when opening a PR, drafting or improving a PR description, preparing a branch for review, or adding reviewers on GitHub.