OpenClaw with Apple

Warn

Audited by Socket on Mar 14, 2026

1 alert found:

Security
SecurityMEDIUM
archive-full-version/SKILL.md

SUSPICIOUS. The core iCloud access is broadly aligned with the stated purpose and uses normal PyPI installs, but the skill expands into persistent location tracking, reverse-geocoding, and autonomous shared-calendar publishing. The main risk is disproportionate privacy impact and credential/session forwarding to third-party libraries, not confirmed malware.

Confidence: 88%Severity: 74%
Audit Metadata
Analyzed At
Mar 14, 2026, 11:52 AM
Package URL
pkg:socket/skills-sh/rtjowo%2Fapple%2Fopenclaw-with-apple%2F@fa73a1e3c6e66e43f146bc0b8dd413dfc6e60b97