iap-finalizer
Warn
Audited by Socket on Aug 2, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS/HIGH-RISK vulnerable skill, not confirmed malware. Its stated purpose and Apple API targets are coherent, but the core operation relies on an unverifiable local helper (asc.py) that handles App Store Connect credentials and performs write actions; under the required scoring rules, that black-box credentialed executable path drives the risk high.
Confidence: 86%Severity: 82%
Audit Metadata