What does this skill do, and when should you use it?
cua-spaces is an Agent Skill from the trycua/cua repository that exposes Cua Spaces capabilities as MCP tools. A Space is a local or remote computer: the user's own machine (free), another machine they own (hosted via cua host setup), or a metered cloud instance. The agent can run shell commands, read/write and upload/download files, show the desktop or a single window to the user, start coding agents inside the Space, teleport a signed-in app session into it, or share the host's network for VPN/intranet access. The skill also carries safety rules, such as previewing a teleport via teleport_manifest and requiring explicit user acknowledgement for sensitive items.
- Lists, creates, starts/stops and deletes Spaces; prefers reusing existing ones and reminds you to delete cloud Spaces when done to stop metering
- Runs shell commands inside a Space (space_bash), writes files (space_write), uploads/downloads folders (upload/download), and drops host files with sha256 verification (send_file)
- Shows the desktop or one window to the user via open_space_viewer, show_space_pip and stream_space_window, with ticketed media URLs (stream_endpoint)
- Queries which agent harnesses a Space supports (agent_capabilities) and starts, follows, steers and stops agent runs (agent_start, agent_status, agent_message, agent_stop)
- Previews with teleport_manifest and moves a signed-in app session (tabs, profile) into a Space with teleport_app
- Shares the host's network with a Space via hotspot_start/status/stop; supports deploying a Space host on machines reachable only over ssh (Tailscale or LAN)
- A developer who needs an isolated environment: run untrusted scripts or experimental dependencies in a disposable Space while watching it live in picture-in-picture
- A user with a spare Mac mini: turn the idle machine into a Space host over ssh/Tailscale so agents on the laptop can use it remotely
- A team working inside a specific network: have a Space share the host's VPN or intranet (hotspot) to reach internal systems, then stop the hotspot afterwards
- A user who wants a signed-in app (Chrome, Slack) carried into an isolated desktop: use Teleport so the session keeps working inside the Space
- An automation user who wants coding agents running in the background: start an agent run in a Space and steer or stop it via agent_status/agent_message
- Fully offline environments or users who cannot install the cua CLI / log in to cua.ai: all tools come from the cua MCP server (cua mcp); if tools are missing the user must run cua agents setup or cua auth login
- Cost-sensitive, one-off tasks with no cleanup discipline: cloud Spaces are metered, and the skill explicitly says to delete the ones you created when the task ends
- Spaces app hosting on Windows (per this documentation): the app install and hosting instructions target macOS 26 or later (LaunchAgent, Screen Recording and Accessibility grants)
How do you install this skill?
- Destructive or metered operations (delete_space, stop_space) should be double-confirmed with the user before execution.
- Core functionality depends on the cua.ai install script, relay and cloud services, which may be unreachable or heavily limited from mainland-China networks; verify connectivity before use.
- Cua Spaces core components are FSL-1.1-MIT source-available, not MIT; read LICENSING.md and COMMERCIAL.md for hosting/commercial use.
- This is a static source review; no tools were executed and all reliability conclusions are inference with low confidence.
- hotspot shares the host's network with the Space; stop it promptly when not needed and mind intranet exposure.
- Shell / CLI
- Network access
- Local filesystem
- MCP Server
cua CLI / cua MCP server (cua mcp)cua.ai account (cua auth login)
The skill lives at libs/cua/skills/cua-spaces/SKILL.md in the trycua/cua repo, part of a bundle of cua skills. The repo documents no per-skill install command; the official entry point is a one-shot installer that adds the cua CLI, the Cua Spaces app, and offers to install cua skills and the cua MCP server into your AI coding agents (Claude Code, Codex, Cursor, and others):
General (macOS / Linux)
curl -fsSL https://cua.ai/install.sh | shWindows (PowerShell)
irm https://cua.ai/install.ps1 | iexIf the skill's MCP tools are missing in your agent, ask the user to run:
cua agents setup
cua auth loginHow do you use this skill?
Once installed, send your agent any of these to trigger it:
- Run uname -a inside a Space and show me the output
- Test this script in a fresh cloud Space, delete the Space when done, and show me the desktop in picture-in-picture
- Teleport my Chrome session into a Space, but first tell me what will be copied
- Give the Space my machine's network so it can reach our intranet, then stop the hotspot when finished
Trigger: the user mentions Spaces, asks to do work "in a Space", or wants a task isolated but visible. The skill works through tools exposed by the cua MCP server (cua mcp). Typical flow: run list_spaces to see what's available; if nothing fits, create_space with on = local (free), cloud (metered) or host:<name> (a user machine registered via cua host setup), optionally reuse: true to get a reachable one first. Work with space_bash, space_write, upload/download and send_file; show progress with open_space_viewer or show_space_pip; manage coding agents with agent_start and friends. Key options and rules: prefer existing Spaces; delete cloud Spaces you created when the task ends; run teleport_manifest and get user acknowledgement before teleport_app; start a hotspot only when the Space needs the host's network (VPN, intranet) and stop it afterwards; name the Space you used in your answer.
What are this skill's strengths and limitations?
- Complete tool coverage: creation, execution, file transfer, screen streaming, agent orchestration and network sharing in one MCP toolset
- Built-in safety guardrails: teleport requires a preview plus explicit user acknowledgement of sensitive items; hotspots are opt-in and turned off afterwards
- Multiple hosting options: local machine (free), your own machines (including ssh-only ones), and your own cloud — no vendor lock-in on infrastructure
- Hard dependency on the cua MCP server and a cua.ai account; if tools go missing, the user must manually run setup/login
- Cloud Spaces are metered and forgetting to delete them costs money; the docs show no automatic cleanup
- Hosting setup is demanding: requires an active GUI login session and one-time Screen Recording and Accessibility grants; auto-login is recommended for a headless Mac mini
How does this skill compare with similar options?
Side by side with related skills; every score comes from the same FSRS standard.
| Skill | FS score | Stars | Last updated | License |
|---|---|---|---|---|
| Cua Spaces (cua-spaces skill) this page | 46 · Use with care | ★ 29k | 1d ago | MIT |
| Cua Driver GUI Automation Skill | 61 · Recommended | ★ 29k | 1d ago | MIT |
| Cua Driver Skill | 58 · Recommended | ★ 29k | 1d ago | MIT |
| Cross-Platform Screenshot Capture ✓ OpenAI · Official | 46 · Use with care | ★ 28k | 3mo ago | — |
| cmux Cloud VM Skill | 56 · Use with care | ★ 28k | 1d ago | NOASSERTION |
The same repository ships Cua Driver (inspect and operate native apps on macOS/Windows/Linux directly, with no isolated Space) and Lume (local macOS/Linux VMs on Apple Silicon via Virtualization.Framework); if you only need to drive the desktop you are on rather than an isolated environment, Cua Driver is the better fit.
How did FollowSkills review this skill?
The skill file has explicit safety rules: teleport_manifest must run before teleport_app with explicit user acknowledgement, hotspots only when needed and stopped afterwards, and the Space used must be named in the answer; data flows (host network sharing, media URLs, sha256-verified send_file) are basically disclosed. Deductions: no confirmation required before destructive operations (delete_space deletes the sandbox and stops metering); the curl|sh install script is not signature-verified; cloud billing risk rests on one reminder; no rollback guidance. Risks are visible but confirmation and recovery are incomplete, so a mid-range score.
Instructions are self-consistent, tool tables are well structured, failure paths are hinted (missing tools prompt cua agents setup / cua auth login), and host setup notes known limitations (Aqua session, Screen Recording grant). But this is a static read only: nothing executed, no skill-level tests or error-feedback examples, and behavior on abnormal inputs (missing tools, network failure, auth failure) is not covered — deducted accordingly.
The frontmatter description states clear triggers (user mentions Spaces, wants work 'in a Space'), tool use cases are well layered, and non-fit boundaries (direct: cannot host new Spaces) are noted. Deductions: core function depends on the cua.ai relay and cloud services with no statement on reachability from mainland China; Chinese-language support is not mentioned; cloud billing boundaries are only briefly described.
Documentation is well layered (tabular tool lists, sectioned scenarios, a Rules section), and the repo has an MIT license, SECURITY.md, contribution and maintenance paths, with stable naming and parameters. Deductions: SKILL.md itself has no version or changelog; many key behaviors depend on external docs at cua.ai/docs; Spaces components are FSL-1.1-MIT source-available rather than MIT, and this licensing boundary is not flagged inside the skill file.
The skill delivers via MCP tool references; with the cua MCP server installed it can complete tasks quickly and offers isolation capabilities beyond manual work, with the value claim supported in the README. Deductions: static review cannot verify actual tool availability or output quality, value depends on external installation and cloud/relay services, and direct-usability evidence is limited.
The repository contains real CI workflows, SECURITY.md, CITATION.cff and multiple test files — auditable primary material — and the README clearly separates MIT from FSL parts and warns about deprecated packages, with good fact/inference separation. Deductions: none of this evidence directly covers the cua-spaces skill path; there are no tests or third-party reproduction targeting the skill itself, so it sits below the static cap.
Open a dimension to read why it scored that way
Evidence confidence:Low — Mostly static review, author material or a limited demo; useful for discovery, not high-risk decisions.
See the full review method →