Interceptor

Fail

Audited by Socket on Aug 15, 2026

2 alerts found:

SecurityMalware
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally coherent for a real-browser/macOS computer-use tool, and I do not see clear third-party credential exfiltration or hidden malware behavior. However, it enables high-impact autonomous actions in real authenticated sessions, uses a broad unauthenticated local bridge with inherited TCC permissions, and depends on a non-registry install path, making it a high-security-risk but not clearly malicious skill.

Confidence: 89%Severity: 81%
MalwareHIGH
Workflows/DriveRichEditor.md

The provided fragment is highly suspicious and appears to be malicious or at least dual-use with a strong data-harvesting intent: it instructs how to covertly intercept client-side export artifacts by patching URL.createObjectURL and anchor click behavior, then extracting raw bytes from blob URLs via fetch(...).arrayBuffer(). No exfiltration or persistence is shown in the fragment itself, but the core mechanism directly enables unauthorized capture of generated export data.

Confidence: 78%Severity: 85%
Audit Metadata
Analyzed At
Aug 15, 2026, 06:48 PM
Package URL
pkg:socket/skills-sh/danielmiessler%2Flifeos%2Finterceptor%2F@f1c04ab8151316198feaa081b014aaf6f853ec13
Security Audit — socket — Interceptor