apple

Warn

Audited by Socket on Apr 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS due to install-trust concerns, not behavior. The skill's purpose and local data flows are coherent for an Apple OAuth emulator, but its core dependency is an unpinned `npx` package whose publisher/provenance is not established in the skill, raising supply-chain risk. No evidence of credential harvesting, third-party proxying, or malicious exfiltration appears in the instructions themselves.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Apr 1, 2026, 10:43 AM
Package URL
pkg:socket/skills-sh/vercel-labs%2Femulate%2Fapple%2F@7f24197cc3a7f761ea538ee8c502abc07cf4e09c