applescript
Warn
Audited by Socket on Sep 14, 2026
1 alert found:
AnomalyAnomalyreferences/advanced-patterns.md
LOWAnomalyLOW
references/advanced-patterns.md
No clear malicious behavior or concealed supply-chain payload is present. The code is an automation utility whose core behavior is intentionally capable of executing arbitrary AppleScript/JXA. That capability is a significant security risk when exposed to untrusted scripts or parameters. The JXA blocklist and manual template escaping provide limited protection, and the omitted parameter validator prevents complete validation of the template path. The code is not intentionally obfuscated, but should be restricted to trusted inputs and reviewed for authorization boundaries.
Confidence: 96%Severity: 67%
Audit Metadata