cua-driver

cua-driver is a skill for Claude Code, Codex from oneworks-ai/app. It costs 50 tokens per session (1,044 once invoked), scanned A, original, MIT.

A skill for controlling native macOS applications through an on-screen computer-control tool. It can interact with apps while keeping the user's active application and physical mouse undisturbed.

In plain words
What is it for?
Use it to open apps, click controls, type text, scroll, capture screenshots, and verify results in a visible macOS application.
Why use it?
It lets an AI agent inspect or operate real macOS apps when file or command-line access is not enough.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/oneworks-ai/app/cua-driver
Any agent
npx skills add oneworks-ai/app --skill cua-driver
Clone the repo
git clone --depth 1 https://github.com/oneworks-ai/app

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for cua-driver

README.md
[![agentmods](https://agentmods.dev/badge/skills/oneworks-ai/app/cua-driver.svg)](https://agentmods.dev/skills/oneworks-ai/app/cua-driver)
Your own site
<a href="https://agentmods.dev/skills/oneworks-ai/app/cua-driver"><img src="https://agentmods.dev/badge/skills/oneworks-ai/app/cua-driver.svg" alt="Measured on agentmods" height="20"></a>
Per session 50 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,044 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00050 $0.01044
Opus 5 $0.00025 $0.00522
Sonnet 5 $0.00010 $0.00209
Haiku 4.5 $0.00005 $0.00104

Measured 3d ago against content hash a5ff729555d9, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

cua-driver scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

packages/plugins/cua-driver/skills/cua-driver/SKILL.md · 47 lines

How it starts

The opening of the file, as written. The whole thing — 47 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Computer Control - CUA

Use the Cua Driver MCP tools contributed by this plugin. OneWorks owns the session and agent loop; the plugin runtime owns driver installation, daemon startup, permission preflight, and the long-lived MCP transport.

User Contract

The user only describes the desired macOS outcome. Do not ask them to run setup commands, start a daemon, resolve a binary, or check permissions. Do not expose those prerequisites as task steps. If macOS requires a new Accessibility or Screen Recording grant, explain the specific system permission and retry the original action after it is granted.

Keep the user's frontmost app frontmost. Use Cua Driver tools whenever an action touches native GUI state. Do not substitute open, mutating AppleScript, cliclick, raw desktop screenshots, or foregrounding shortcuts; those paths can activate apps, move the real cursor, switch Spaces, or bypass the driver's evidence trail.

The plugin runtime automatically prepares a visible virtual Agent pointer before exposing the tools. The physical mouse remains untouched. Each session receives its own stable automatic color. Every workflow starts its pointer from the main-display center unless cursor_start is provided. If the user requests a particular color, pass cursor_color; if they request a particular starting point, pass logical main-display coordinates through cursor_start. For low-level recovery calls, use set_session_cursor_color or set_session_cursor_start once before the next pointer action. Do not add daemon setup commands, raw cursor-style operations, or arbitrary pointer-motion steps to the task.

Action Protocol

Prefer execute_workflow whenever one app has two or more actions known in advance. When independent work is ready for multiple apps, submit it once with execute_workflows; different app resources may advance concurrently, workflows touching the same app remain serial, and pointer actions retain the global safety lock. Use resume_workflow only after a returned agent/user checkpoint. Use get_workflow_step_results only when the compact result does not contain enough detail. Read WORKFLOWS.md before composing a workflow.

Read the full file on GitHub · 47 lines

Files

What ships with it

3 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 3d ago First seen · 47 lines · 50 tokens per session scan A a5ff729555d9

Subscribe to this mod's changes

cua-driver is a skill published in the GitHub repository oneworks-ai/app (18 stars, last pushed 4d ago), licensed MIT. It adds 50 tokens to every session and 1,044 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

neo4j-modeling-skill

Design, review, and refactor Neo4j graph data models. Use when choosing node labels vs relationship types vs properties, migrating relational/document schemas to graph, detecting anti-patterns (generic labels, supernodes, missing constraints), designing intermediate nodes for n-ary relationships, enforcing schema with…

neo4j-contrib/neo4j-skills · 152 tokens

alphafold-database

Access AlphaFold 200M+ AI-predicted protein structures. Retrieve structures by UniProt ID, download PDB/mmCIF files, analyze confidence metrics (pLDDT, PAE), for drug discovery and structural biology.

agent-skills-hub/agent-skills-hub · 54 tokens

lov-env-management

统一管理平台、账号与多组 API Key,维护有效期和启用状态,安全同步到 zsh 或用户会话环境,并提供脱敏 Dashboard;用户说“管理环境变量”“rotate API keys”时使用。.

lovstudio/skills · 53 tokens

lov-deploy-to-vercel

Deploy frontend projects to Vercel with automatic custom domain setup. Handles Vite, Next.js, CRA, and static sites. Auto-configures Cloudflare DNS CNAME records and Vercel domain aliases. Supports SPA routing via vercel.json. Trigger when user says "deploy to vercel", "部署到 vercel", "vercel deploy", or mentions a…

lovstudio/skills · 92 tokens

lov-bp-outline

Turn existing project materials into a source-backed investor BP brief, evidence ledger, and 12–15 slide outline. Use before making slides, when the product positioning is unclear, or when an existing outline is too technical, generic, or unsupported. Trigger on "写 BP 大纲", "融资叙事", "梳理商业计划书", "先不要做 PPT", "BP outline"…

lovstudio/skills · 97 tokens

github-create-pr

Create GitHub pull requests from a local branch using a reviewable workflow for branch checks, diff analysis, PR title/body writing, and gh CLI creation. Use when opening a PR, drafting or improving a PR description, preparing a branch for review, or adding reviewers on GitHub.

flc1125/skills · 61 tokens