apple-app-store-reviewer

Fail

Audited by Socket on Aug 26, 2026

1 alert found:

Malware
MalwareHIGH
tests/fixtures/project-bad/App.swift

This fragment contains multiple high-risk supply-chain indicators: a credential-like hardcoded token and an explicit `dlopen` call to load a native library at runtime. Even without additional exfiltration/network/file behavior shown in the excerpt, runtime native library loading is a powerful arbitrary code execution primitive and is strongly consistent with malware/backdoor scaffolding. The snippet should be treated as suspicious and requires full context review of call paths, library resolution/location, and whether/where the token/endpoint are used.

Confidence: 65%Severity: 92%
Audit Metadata
Analyzed At
Aug 26, 2026, 10:28 AM
Package URL
pkg:socket/skills-sh/codealive-ai%2Fai-driven-development%2Fapple-app-store-reviewer%2F@3801c240a9fd9f22d8b5a3423fa92d152210965f85e24535a968476fb4be950b
Security Audit — socket — apple-app-store-reviewer