convert-to-apple-container

Warn

Audited by Socket on Apr 26, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core runtime-conversion workflow is broadly consistent with the stated purpose, and the Apple Container download source appears proportionate. The main concern is the deliberate instruction to expose a credential proxy on 0.0.0.0, with only conditional firewall mitigation, plus privileged firewall edits and remote branch merging. This looks more like a risky operations skill than outright malware.

Confidence: 87%Severity: 72%
Audit Metadata
Analyzed At
Apr 26, 2026, 09:53 PM
Package URL
pkg:socket/skills-sh/qwibitai%2Fnanoclaw%2Fconvert-to-apple-container%2F@8b23a836a0e98c0b3e6226bab7bb63d623986723