maintaining-macos-health

Warn

Audited by Socket on Sep 15, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
references/cleanup-tiers.md

This is a destructive macOS storage-cleanup playbook, not clear malware. It contains no evident data theft, network communication, credential collection, persistence, or obfuscated payload. However, executing the commands can irreversibly delete user data, application state, projects, logs, Docker data, and potentially system-relevant files, especially when run with sudo or when safeguards are skipped. It should be treated as high operational risk and executed only after independently verifying every target and maintaining backups.

Confidence: 98%Severity: 82%
SecurityMEDIUM
assets/apply-cleanup-selection.py

The fragment appears intended as a cleanup-selection executor rather than malware, but it has a serious command-injection design flaw. Untrusted or tampered selection JSON can supply shell syntax through any accepted wrapper prefix and obtain arbitrary command execution. The selection file must therefore be treated as fully trusted, or execution should be changed to a strict argument-array model with a narrowly defined executable allowlist and no shell=True. No direct evidence of credential theft, persistence, network exfiltration, or cryptomining is present in this fragment.

Confidence: 98%Severity: 88%
Audit Metadata
Analyzed At
Sep 15, 2026, 04:11 AM
Package URL
pkg:socket/skills-sh/codealive-ai%2Fai-driven-development%2Fmaintaining-macos-health%2F@5a84bfc88af34ec7300a6235f0efc28fbc5dc2ff822fb253d75a575294cd324f
Security Audit — socket — maintaining-macos-health