macos-admin

Fail

Audited by Socket on Mar 7, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's stated purpose as a macOS admin automation tool is broadly coherent with its capabilities. However, the footprint raises several security concerns: reliance on elevated privileges, handling of admin credentials via environment variables, and the ability to enable/disable core security features (SIP, FileVault) and manage users. Without strict per-action approval, input validation, least-privilege execution, and secure credential handling (e.g., using keychain or token-based authentication rather than env vars), this skill leans toward a high-risk, potentially destructive tool. It is reasonable for legitimate enterprise workflows if paired with rigorous access controls, auditing, and explicit user consent for each sensitive operation; otherwise, classify as Suspicious due to privilege scope and credential handling risks.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 7, 2026, 05:46 PM
Package URL
pkg:socket/skills-sh/alphaonedev%2Fopenclaw-graph%2Fmacos-admin%2F@530c1fa8d7d916ef0d29b10eaf9181088fd804fb