macos-automator

Fail

Audited by Socket on Feb 26, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

Functionally correct for macOS automation but high-risk by design: the skill grants broad privileges (arbitrary AppleScript/JXA and shell execution, accessibility reads, filesystem and clipboard access) without described sandboxing, input validation, or KB provenance controls. That creates straightforward paths for credential harvesting and data exfiltration if a caller or the KB is malicious or compromised. No explicit malicious code was identified in the provided text, but operational and supply-chain mitigations are required before allowing untrusted callers to use this capability.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 26, 2026, 10:20 PM
Package URL
pkg:socket/skills-sh/SZoloth%2Fskills%2Fmacos-automator%2F@c52e89c647fe972aba2e9b27eb557562d2e4155b