applescript

Warn

Audited by Socket on Sep 14, 2026

1 alert found:

Anomaly
AnomalyLOW
references/advanced-patterns.md

No clear malicious behavior or concealed supply-chain payload is present. The code is an automation utility whose core behavior is intentionally capable of executing arbitrary AppleScript/JXA. That capability is a significant security risk when exposed to untrusted scripts or parameters. The JXA blocklist and manual template escaping provide limited protection, and the omitted parameter validator prevents complete validation of the template path. The code is not intentionally obfuscated, but should be restricted to trusted inputs and reviewed for authorization boundaries.

Confidence: 96%Severity: 67%
Audit Metadata
Analyzed At
Sep 14, 2026, 05:54 PM
Package URL
pkg:socket/skills-sh/martinholovsky%2Fclaude-skills-generator%2Fapplescript%2F@3e63ba790225808f24fef5add739dad94777420a286e9efcaad778fd1275dfc9
Security Audit — socket — applescript