swift-macos

Warn

Audited by Socket on May 1, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
references/spm-build.md

No direct malware behavior is evident in the provided fragment (no exfiltration, credential theft, backdoor logic, or obfuscation). However, the module contains a meaningful supply-chain risk surface: it runs external binaries during the build (code generation and recursive formatting via SPM plugins) and then manually copies and codesigns frameworks/resources from build artifacts. If the resolved codegen/formatter tools or build outputs are compromised/tampered, malicious code could be introduced and signed. Overall risk is driven by build-time tool/artifact integrity rather than runtime malicious behavior.

Confidence: 63%Severity: 56%
AnomalyLOW
references/system-integration.md

No explicit malware behavior is visible in this fragment (no network exfiltration, code execution primitives, or credential theft). However, the included system-integration capabilities—especially per-process audio/input-output detection, running-app monitoring, and login-item persistence scaffolding—are privacy-sensitive and could be misused. Based on the snippet alone, treat as a medium security risk due to surveillance/persistence potential, but malware presence is not confirmed.

Confidence: 62%Severity: 55%
Audit Metadata
Analyzed At
May 1, 2026, 10:52 AM
Package URL
pkg:socket/skills-sh/tenequm%2Fskills%2Fswift-macos%2F@6f2250e47acd1d940bd12c3f37b54e3dfefd593a