macbroom

Warn

Audited by Socket on Mar 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The instruction file describes legitimate macOS cleanup tasks and appropriate CLI usage patterns. The file itself contains no apparent malicious code or obfuscation, but it does contain operationally risky recommendations: a third-party Homebrew tap for installation (supply-chain risk) and commands capable of permanent data loss if executed without explicit, per-action user confirmation. lanchr integration introduces further uncertainty about snapshot storage/transmission. Overall I assess low likelihood of intrinsic malware in this document but a moderate security risk driven by installation source and the potential for destructive, automated actions. Recommend verifying binary provenance and enforcing explicit confirmations before destructive operations.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 4, 2026, 03:32 AM
Package URL
pkg:socket/skills-sh/lu-zhengda%2Fmacos-toolkit%2Fmacbroom%2F@1e023b0dead5221f0f14ee9a9b75eeec24f99644