macos-computer-use
Warn
Audited by Socket on Mar 16, 2026
1 alert found:
AnomalyAnomalyreferences/apis.md
LOWAnomalyLOW
references/apis.md
This file is API documentation describing macOS window enumeration, window-level screenshot capture, and synthetic input event techniques. The fragment itself contains no executable malicious code, no obfuscation, and no hardcoded secrets. However, it documents powerful primitives that can be abused for surveillance, credential harvesting, or automated unauthorized interaction with other applications. If these APIs are used in an accompanying package, reviewers should treat implementations as moderate-to-high risk and audit for screenshot storage, clipboard usage, network exfiltration, and whether user consent/privileges are properly requested and limited.
Confidence: 90%Severity: 60%
Audit Metadata