iap-finalizer

Warn

Audited by Socket on Aug 2, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK vulnerable skill, not confirmed malware. Its stated purpose and Apple API targets are coherent, but the core operation relies on an unverifiable local helper (asc.py) that handles App Store Connect credentials and performs write actions; under the required scoring rules, that black-box credentialed executable path drives the risk high.

Confidence: 86%Severity: 82%
Audit Metadata
Analyzed At
Aug 2, 2026, 01:18 PM
Package URL
pkg:socket/skills-sh/rshankras%2Fclaude-code-apple-skills%2Fiap-finalizer%2F@b967cb7d3cd8f72bbb6ded7957a98f62e4b0ba211fc19735b503780a4e7c481f
Security Audit — socket — iap-finalizer