convert-to-apple-container

Warn

Audited by Socket on Mar 12, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill purpose is coherent: it aims to switch the runtime from Docker to Apple Container on macOS. However, the footprint includes a significant security risk due to reliance on downloading an unverifiable external binary (Apple Container) and executing privileged operations (root containers, bind mounts, privilege dropping). While the feature set aligns with the stated macOS-native runtime objective, the combination of external binary installation, potential for privilege-related risks, and unverified supply-chain posture elevates the risk profile to Suspicious. If the binary integrity, signatures, and pinning are verified and a trusted supply-chain process is established, the risk could be mitigated toward Benign; as-is, treat as Suspicious with a need for stronger verification and controlled execution gates.

Confidence: 98%Severity: 75%
Audit Metadata
Analyzed At
Mar 12, 2026, 02:35 PM
Package URL
pkg:socket/skills-sh/qwibitai%2Fnanoclaw%2Fconvert-to-apple-container%2F@9130f5179496c95aa1bbf9a50c3b1d29132678c3