desktop-app-flows

Warn

Audited by Socket on Mar 23, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The stated purpose is coherent for desktop UI exploration, and there is no clear credential harvesting or exfiltration path. However, the skill’s core dependence on an unverifiable external CLI (`agent-swift`) materially raises trust risk, especially because that CLI can read broad accessibility/UI data and drive live app actions. Main concern is supply-chain and local data exposure, not confirmed malware.

Confidence: 84%Severity: 74%
Audit Metadata
Analyzed At
Mar 23, 2026, 03:40 PM
Package URL
pkg:socket/skills-sh/basedhardware%2Fomi%2Fdesktop-app-flows%2F@156b3d6442bc1296819deac1136f0f9cfe4c71e7