synthesis-mac-sync

Warn

Audited by Socket on Mar 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core file/repo sync behavior is coherent with the stated purpose and uses normal tools, but the skill's footprint is broadened by arbitrary shell execution from a markdown config file, autonomous Git push/pull behavior, and syncing of sensitive credential files into iCloud. There is no clear malware payload or deceptive third-party credential relay, but the combination makes this a high-risk automation skill rather than a benign narrow sync helper.

Confidence: 87%Severity: 78%
Audit Metadata
Analyzed At
Mar 20, 2026, 05:08 PM
Package URL
pkg:socket/skills-sh/rajivpant%2Fsynthesis-skills%2Fsynthesis-mac-sync%2F@2da59bab9066f5a9bfafa18aea9aa870cee8d7b7