apple-events

Warn

Audited by Socket on May 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The local calendar/reminder access matches the stated purpose, but the skill's core dependency is an unverifiable `event` CLI and that same CLI is expected to receive a sync API token and transmit personal data to a configured backend. The remote sync design is plausible, yet the missing provenance for the executable creates a high supply-chain and credential-forwarding risk.

Confidence: 83%Severity: 84%
Audit Metadata
Analyzed At
May 28, 2026, 09:24 PM
Package URL
pkg:socket/skills-sh/FradSer%2Fevent%2Fapple-events%2F@bb6d4a2a5931e76043346c9ca2dc044500d824d7
Security Audit — socket — apple-events