mole-mac-cleanup

Fail

Audited by Socket on Feb 17, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

[Skill Scanner] Installation of third-party script detected All findings: [CRITICAL] command_injection: Installation of third-party script detected (SC006) [AITech 9.1.4] [HIGH] data_exfiltration: Credential file access detected (DE002) [AITech 8.2.3] This skill description documents a legitimate-looking macOS cleanup/optimization CLI that requires broad filesystem access and occasional privileged operations. The actions requested are consistent with its purpose, but they are high-risk (can delete user data or alter system state). There is no evidence here of obfuscation, credential harvesting, or network exfiltration. Treat the tool as potentially dangerous if run without review or without dry-run/whitelist checks; prefer human oversight and inspect the actual 'mo' binary/source before allowing automated agents to execute destructive commands. LLM verification: This SKILL.md documents a legitimate-seeming macOS cleanup/optimization tool whose capabilities (deleting caches, purging build artifacts, rebuilding system indexes, configuring Touch ID/sudo) are consistent with its stated purpose. The primary security concerns are operational: the tool requires elevated privileges and wide filesystem access (which is expected for its function) and the documentation does not specify secure, verifiable update endpoints. Because privileged delete operations can c

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 17, 2026, 01:33 AM
Package URL
pkg:socket/skills-sh/bjesuiter%2Fskills%2Fmole-mac-cleanup%2F@5447421fd15d1642f3d72c48e8de5ef5cbb817ca