OpenClaw with Apple
Warn
Audited by Socket on Mar 14, 2026
1 alert found:
SecuritySecurityarchive-full-version/SKILL.md
MEDIUMSecurityMEDIUM
archive-full-version/SKILL.md
SUSPICIOUS. The core iCloud access is broadly aligned with the stated purpose and uses normal PyPI installs, but the skill expands into persistent location tracking, reverse-geocoding, and autonomous shared-calendar publishing. The main risk is disproportionate privacy impact and credential/session forwarding to third-party libraries, not confirmed malware.
Confidence: 88%Severity: 74%
Audit Metadata