macfig

Warn

Audited by Socket on Mar 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The file documents a legitimate macOS preferences management tool. There are no direct signs of malware, remote exfiltration, or embedded credentials. The highest practical risk is misuse: the ability to run any macfig subcommand (wildcard allowed-tools) and to import arbitrary JSON enables high-impact local changes and accidental persistence of potentially sensitive preference data. Treat this tool as high-impact configuration software: restrict execution privileges, require confirmations/dry-runs for bulk operations, validate imported data, and ensure backups/exports are stored securely.

Confidence: 98%Severity: 75%
Audit Metadata
Analyzed At
Mar 4, 2026, 03:32 AM
Package URL
pkg:socket/skills-sh/lu-zhengda%2Fmacos-toolkit%2Fmacfig%2F@db4c6d8f261c304c355eabc253e15e4c0ce6ff76