macos-computer-use

Warn

Audited by Socket on Mar 16, 2026

1 alert found:

Anomaly
AnomalyLOW
references/apis.md

This file is API documentation describing macOS window enumeration, window-level screenshot capture, and synthetic input event techniques. The fragment itself contains no executable malicious code, no obfuscation, and no hardcoded secrets. However, it documents powerful primitives that can be abused for surveillance, credential harvesting, or automated unauthorized interaction with other applications. If these APIs are used in an accompanying package, reviewers should treat implementations as moderate-to-high risk and audit for screenshot storage, clipboard usage, network exfiltration, and whether user consent/privileges are properly requested and limited.

Confidence: 90%Severity: 60%
Audit Metadata
Analyzed At
Mar 16, 2026, 03:48 PM
Package URL
pkg:socket/skills-sh/robinebers%2Fskills%2Fmacos-computer-use%2F@30a0102c70e1cf2b3aad2d3e23b15855958ffcf0