What does this skill do, and when should you use it?
cmux-cua is a skill bundled with the cmux macOS terminal that attaches an MCP tool server named cmux-cua to every agent session cmux launches (Claude Code, Codex). The agent can then read the accessibility tree, take screenshots, and click, type, scroll, and drag in real macOS apps. Everything runs locally through a separate cmux Computer Use helper that owns its own TCC permissions, so Accessibility and Screen Recording never belong to the main app. The skill explicitly forbids any automatic invocation without a direct user request.
- Attaches the cmux-cua MCP tool roster to cmux-launched Claude Code / Codex sessions via wrappers
- get_app_state / get_window_state return a screenshot plus a compact accessibility tree; actions address elements or pixels
- Provides click, type_text, press_key, scroll, drag, set_value, select_text and related tools
- Shows a branded gradient cursor (cmux logo colors) so the agent's pointer is visible on screen
- Walks through one-time macOS Accessibility and Screen Recording (TCC) grants without the main cmux process ever holding them
- A menu-bar item offers Focus Computer Use / Focus Calling Terminal presentation modes for the driving session
- A developer running parallel Claude Code sessions in cmux who needs the agent to operate real GUI apps such as Calculator or System Settings
- A Codex user who wants visible pointer clicks on on-screen controls instead of pure keyboard input
- Automation flows where the agent must verify GUI changes via screenshot plus accessibility tree before proceeding
- Users who want pixel input blocked with a background_occluded safety stop rather than clicking the wrong covered window
- Non-macOS users — the skill depends entirely on macOS Accessibility, Screen Recording, and TCC mechanisms
- Users who do not run the cmux app — tools attach only to cmux-launched, live-socket sessions, so standalone Claude Code or Codex installs get nothing
- Headless or restricted environments (CI, no GUI desktop) or users unwilling to grant Screen Recording and Accessibility permissions
How do you install this skill?
- The skill requests macOS Accessibility and Screen Recording and can observe and operate real application UIs; invoke only on explicit user request and check which app holds the grants in System Settings.
- The skill installs via symlinks into ~/.agents/skills or ~/.claude/skills; link-policy.sh claims to remove only 'managed' links, but that ownership logic has not been independently audited.
- License metadata is NOASSERTION: the repo mixes GPL-3.0-or-later with BUSL-1.1 and the engine lives in a separate fork; verify compliance before commercial use.
- macOS-only and requires a cmux-launched session; documentation is English-only; this is a static source review with no execution or independent testing.
- Shell / CLI
- Local filesystem
- MCP Server
cmux macOS app (tagged build)cmux Computer Use helpermacOS Accessibility permissionmacOS Screen Recording permission
The skill ships inside the cmux app, so installing cmux is the only documented route:
brew tap manaflow-ai/cmux
brew install --cask cmuxAn optional persistent global skill install is app-managed (set CMUX_COMPUTER_USE_INSTALL_GLOBAL_SKILL=1 for a launch, creating a ~/.claude/skills/cmux-cua or ~/.agents/skills/cmux-cua link). No other manual install commands are documented.
How do you use this skill?
Once installed, send your agent any of these to trigger it:
- $cmux-cua open Calculator and compute 128 × 46 for me
- Use cmux Computer Use to check the Screen Recording permission state in System Settings
- $cmux-cua create a new note in Notes titled "Meeting notes
- Via cmux Computer Use, screenshot the current Safari window and list the form fields on the page
Inside a cmux-launched agent session, an explicit functional user request for cmux Computer Use (e.g. $cmux-cua) is the opt-in: if the saved toggle is off, cmux enables the runtime and opens onboarding automatically. The first functional tool call opens setup if permissions are missing (Accessibility + Screen Recording); the user grants each step in System Settings, with an extra direct-capture consent alert on macOS Tahoe. The agent then follows the Codex ten-tool roster or the Claude/native profile (perceive, act in groups, verify). Hard kill switch: CMUX_COMPUTER_USE_MCP_DISABLED=1. Never invoke the skill when the user is only reading or asking about it.
What are this skill's strengths and limitations?
- Fully local; upstream telemetry and update checks disabled at runtime
- Permissions granted to a dedicated helper with its own TCC identity, so granting Screen Recording never requires restarting cmux
- Branded cursor makes agent actions visible and auditable on screen
- Pixel input is obstruction-checked (background_occluded) instead of clicking the wrong covered window
- Mandatory explicit-consent gating prevents agents from starting GUI work on their own
- macOS only, and usable only in sessions launched by the cmux app
- Requires two sensitive system permissions (Accessibility + Screen Recording)
- Catalyst apps (e.g. Calculator) can briefly expose an empty AX tree and spurious error -25204, requiring re-snapshots
- Background coordinate drags are unavailable on macOS; must use delivery_mode:"foreground"
- Clicks are never helper-verified; verification relies entirely on re-snapshotting
- Repo license is NOASSERTION (README states GPL-3.0-or-later for the app, BUSL 1.1 for server components)
How does this skill compare with similar options?
Side by side with related skills; every score comes from the same FSRS standard.
| Skill | FS score | Stars | Last updated | License |
|---|---|---|---|---|
| cmux Computer Use Skill this page | 50 · Use with care | ★ 28k | 1d ago | NOASSERTION |
| Cua Driver Skill | 58 · Recommended | ★ 29k | 1d ago | MIT |
| Cua Driver GUI Automation Skill | 61 · Recommended | ★ 29k | 1d ago | MIT |
| Cua GUI Automation Skill | 51 · Use with care | ★ 29k | 1d ago | MIT |
| Agent Browser: Deterministic Web Automation | 49 · Use with care | ★ 20k | 7d ago | MIT |
The source contrasts it with Codex's built-in computer_use connector: cmux disables Codex's native provider in its sessions and forces the namespaced cmux-cua tools (exact ten-tool roster, schema parity, but no get_window_state, tokens, recordings, or CDP extensions). It also distinguishes the codex CLI's own computer-use helper — a macOS prompt naming 'Codex Computer Use (com.openai.sky.CUAService)' is not from cmux.
How did FollowSkills review this skill?
Credit: repeated explicit-consent framing (loading is not consent), separate TCC identity, hard kill switch (CMUX_COMPUTER_USE_MCP_DISABLED=1), fail-closed design (no ambient executable override), no implicit invocation (allow_implicit_invocation: false). Deducted: skill drives high-privilege macOS Accessibility/Screen Recording, writes symlinks into user skill directories, and depends on a pinned build from an unverified publisher; isolation/rollback logic is self-declared in scripts, not independently verified.
Credit: extensive abnormal-path coverage (Catalyst AX error -25204, background_occluded guard, unavailable background drags, TCC attribution confusion) with diagnosable named errors and troubleshooting entries; link-policy.sh is self-consistent and defensive. Deducted: static review cannot run any key path; no committed tests covering the skill paths are visible; divergent Claude/Codex wrapper behavior (compat flag) adds inconsistency risk.
Credit: trigger conditions are extremely explicit (only on a direct user $cmux-cua request, disable-model-invocation: true) with clear non-fit boundaries (no silent provider switching). Deducted: macOS + cmux-session-only scope narrows the audience; docs are English-only with no Chinese support statement; usability outside the declared local GUI environment is unverified.
Credit: well-layered document (attachment, permissions, tool usage, troubleshooting, development), agents/openai.yaml interface metadata, heavily commented link policy. Deducted: repository license metadata is NOASSERTION (actual GPL-3.0-or-later plus BUSL mix, with the engine in a separate fork, complicating attribution); no skill-level version or changelog; publisher unverified, with maintenance/update path only indirectly visible at repo level.
Credit: the core task (driving macOS apps via accessibility tree plus screenshots) has concrete tool rosters, operation ordering and verification loops; clear marginal value over manual GUI work. Deducted: direct usability is unverified without execution; some behaviors are self-declared as not independently verified (e.g. drag contract), and real effect depends on users completing multi-step system permission setup.
Credit: key claims trace to concrete in-repo source paths (Packages/macOS/CmuxComputerUse/, wrapper scripts, CMUX_CUA_PINNED_SHA build script). Deducted: the static ceiling is 5; no committed test suite or CI execution evidence covering this skill's key paths; license attribution (NOASSERTION) and publisher identity are not independently checkable.
Open a dimension to read why it scored that way
Evidence confidence:Low — Mostly static review, author material or a limited demo; useful for discovery, not high-risk decisions.
See the full review method →