What does this skill do, and when should you use it?
Cua Volume is an agent skill shipped in the trycua/cua repository alongside Cua Spaces, exposing one versioned volume per user to every Space and agent. The volume is mounted as a folder (/volume on Linux, ~/Cua Volume on macOS), so agents read and write it directly, and writes appear on the user's Mac in Finder and on all devices within seconds. Every write is a new version, deletes keep history, and conflict copies are never lost. It relies on the volume_* tools from the cua MCP server and ships with a strict operating rulebook: folder permissions, sync-state checks, conflict handling, and a hard refusal to store secrets.
- Reads and writes /volume (or ~/Cua Volume) in Linux Spaces and ~/Cua Volume in macOS Spaces, first verifying a real mount with mountpoint -q /volume or ls.
- Falls back to the cua MCP server's volume_ls / volume_read / volume_write where no mount exists (e.g. Windows), showing each file's sync state.
- Uses volume_delete / volume_history / volume_restore (where offered) to delete, inspect old versions, and restore one.
- Uses volume_request_access to ask the user for access to another agent's home or another Space's folder (with r or rw and a reason), approved in Cua.
- Checks volume_sync_status for feed live/off/offline, per-device last sync, pending_upload, conflict, and conflict_copy states.
- Writes user-facing results into agents/<you>/outputs/ or this Space's folder and reports the path; writes to agent homes are scanned for secrets and refused (secret_detected) when found.
- Users running long agent tasks: save results to agents/<you>/outputs/ so they survive even after the Space is destroyed.
- People juggling multiple Spaces: share user-provided reference material via public/, visible in every Space within seconds.
- Cross-device workers: see files an agent just wrote directly in Finder on the Mac, with no manual transfer.
- Multi-agent collaboration: one agent requests r or rw access to another agent's home via volume_request_access, approved by the user in Cua.
- Users who need audit and recovery: use volume_history and volume_restore to recover overwritten or deleted versions, with conflict copies preserved automatically.
- Users without Cua Spaces and the Cua ecosystem: the volume backend, Keyvault, and sync all come from the Cua platform; outside it this skill has nothing to operate on.
- Windows users: there is no filesystem mount yet, only the volume_* MCP tools, and the docs give no timeline for a Windows mount.
- Anyone intending to store API keys or passwords in the volume: writes are scanned and refused (secret_detected); secrets belong in the user's Keyvault.
How do you install this skill?
- The skill only works inside the Cua Spaces ecosystem; it is unusable without its mount/tooling environment.
- It depends on cua.ai-hosted services (relay, storage); mainland-China reachability is undeclared and core sync may be limited.
- Security guarantees (secret scanning, access approval, no-loss conflicts) are implemented in the closed-source FSL-licensed backend and could not be verified in this static review.
- No per-skill versioning or changelog; volume_* tools vary by deployment — always run the mount check and volume_sync_status before relying on files.
- Shell / CLI
- Network access
- Local filesystem
- MCP Server
Cua Spaces app and a Cua account (volume backend)cua MCP server (volume_* tools)FUSE mount on Linux Spaces (without /dev/fuse the mount is unavailable)
The install route comes from the repository README: the official installer sets up the cua CLI and the Cua Spaces app, and during cua auth login it offers to install cua skills and the cua MCP server into your AI coding agents (Claude Code, Codex, Cursor, and others).
Claude Code / Codex / Cursor and other coding agents (macOS or Linux)
curl -fsSL https://cua.ai/install.sh | sh
cua auth loginSelect cua skills and the cua MCP server in the installer checklist (you can preselect items with sh -s -- --select cua-driver or skip with --only cua-driver — the README wording targets cua-driver, but skill install goes through the same checklist). The skill itself lives at libs/cua/skills/cua-volume/SKILL.md; no per-skill install command is documented.
How do you use this skill?
Once installed, send your agent any of these to trigger it:
- Save the results of this analysis to your outputs folder — I want to open them on my Mac.
- Read the reference files in public, then write a summary into my Cua Volume.
- Restore the previous version of report.docx from the Cua Volume.
- Request read-write access to the inbox folder in the other agent's home; I need the data it organized.
The skill is triggered by mentions: when the user references the volume, Cua Volume, shared files, your home or memory, or saving results, the agent follows SKILL.md. Typical flow: verify the volume is actually mounted (Linux: mountpoint -q /volume; macOS: ls ~/'Cua Volume'; a /volume containing only CUA-VOLUME-UNAVAILABLE.txt is not the volume); then work within the folder rules — public/ is read-only, agents/<you>/ is your writable home (memory, outputs/, inbox/), spaces/<this space>/ is this Space's scratch area; put deliverables in outputs/ and tell the user the path. Without a mount, or to check sync health, use the MCP tools:
volume_sync_status
volume_ls
volume_read <path>
volume_write <path>Key points: mount writes upload on file close, so close files before telling the user they are ready; on conflicting writes the later one wins and the other is kept as 'name (conflict from <device> <date>).ext' — never delete a conflict copy yourself.
What are this skill's strengths and limitations?
- Every write is a new version, deletes keep history, and conflict copies are never lost — data safety is built into the workflow.
- The same files appear on the user's Mac in Finder and in every Space within seconds.
- Clear permission model: public/ is read-only, other agents' homes are invisible by default, refused writes must go through volume_request_access instead of workarounds.
- Secret scanning: writes to agent homes with API keys or tokens are refused (secret_detected) and logged, preventing accidental secret leakage.
- SKILL.md spells out failure modes in a state table (feed live/off/offline, pending_upload, conflict), so agents know when to wait, when to tell the user, and when not to trust a stale file.
- Hard dependency on the Cua ecosystem: requires the Cua Spaces app, the cua MCP server, and a user account; without the platform the volume does not exist.
- Windows has no filesystem mount yet; only the volume_* tools work, limiting the experience to MCP.
- Linux Spaces need /dev/fuse; containers without FUSE get an unavailable mount and must fall back to the tools.
- Sync is eventually consistent: files written by another device can take a few seconds to arrive, and offline buckets require the agent to detect and stop rather than trust stale files.
- volume_delete / volume_history / volume_restore are documented as 'where offered', so not every environment has them.
How does this skill compare with similar options?
Side by side with related skills; every score comes from the same FSRS standard.
| Skill | FS score | Stars | Last updated | License |
|---|---|---|---|---|
| Cua Volume Skill this page | 52 · Use with care | ★ 29k | 1d ago | MIT |
| Cua Spaces (cua-spaces skill) | 46 · Use with care | ★ 29k | 1d ago | MIT |
| Cua Driver GUI Automation Skill | 61 · Recommended | ★ 29k | 1d ago | MIT |
| Cua Driver Skill | 58 · Recommended | ★ 29k | 1d ago | MIT |
| NemoClaw AI Agent User Guide ✓ NVIDIA · Official | 54 · Use with care | ★ 3.5k | 3d ago | Apache-2.0 |
The README positions the broader repository for general desktop automation: Cua Driver operates native apps and browsers on macOS, Windows, and Linux, whereas cua-volume only handles persistent, synced agent files across Spaces and the user's devices — it provides no desktop-control capability.
How did FollowSkills review this skill?
SKILL.md shows least-privilege design: clear folder-level read/write boundaries (public/ read-only, other agents' homes invisible), refused writes must not be worked around, secret writes are detected and refused (secret_detected), and conflict/restore paths are documented. Deducted: the enforcement mechanisms (secret scanning, access approval) live in the FSL-licensed cua-volume backend, unverifiable from this static read; publisher identity is unverified, attribution rests on repository evidence only.
Instructions are self-consistent with good failure feedback: distinguishes mounted vs unmounted (mountpoint -q /volume), the CUA-VOLUME-UNAVAILABLE.txt diagnostic, sync states (pending_upload/conflict/offline) with last_error guidance. Deducted: no tests or reproduction evidence for this skill's key paths in the provided files; static cap of 10 applies, scored 9.
Trigger semantics in frontmatter are precise (volume, Cua Volume, shared files, saving results), and platform boundaries (Linux/macOS paths, Windows tool fallback) are clear. Deducted: core function is unusable outside Cua Spaces; depends on cua.ai-hosted relay/services with no mainland-China reachability statement and no Chinese-language support noted.
Well-layered documentation: path table, permission layout, tool table, sync/conflict handling, secrets policy, with frontmatter matching content and repo-level LICENSE and SECURITY.md. Deducted: no per-skill version or changelog; tool availability qualified vaguely ('Where offered'); some behavior depends on implementation not present in the file.
Goal is clear (durable cross-Space file persistence and sharing), conflict preservation and sync-state checks make outputs directly usable; real marginal value. Deducted: static review cannot verify execution; value depends entirely on the Cua Spaces ecosystem running; scored within the static cap of 7.
Repository shows CI workflows, test suites, and a substantive SECURITY.md with coordinated disclosure and safe harbor. Deducted: none of this evidence covers the cua-volume skill's key paths (mount detection, secret scanning, conflict semantics lack committed tests in evidence); static cap of 5 applies.
Open a dimension to read why it scored that way
Evidence confidence:Low — Mostly static review, author material or a limited demo; useful for discovery, not high-risk decisions.
See the full review method →