apple-notes

Warn

Audited by Socket on Aug 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s note-management purpose is plausible, but its actual trust model is weak. It relies on an unverified `note` CLI, forwards sensitive sync credentials and note data to a configurable remote endpoint, and references an on-demand fetch script for backend code. The capability set mostly fits the purpose, but install provenance and data-flow integrity are not sufficiently verifiable.

Confidence: 88%Severity: 82%
Audit Metadata
Analyzed At
Aug 18, 2026, 04:29 PM
Package URL
pkg:socket/skills-sh/fradser%2Fnote%2Fapple-notes%2F@26534d46cc3b021f34cd19d520d1fa90f5ee72596a191658ae78cd3061978756
Security Audit — socket — apple-notes