apple-notes-search
Warn
Audited by Socket on Sep 6, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill's purpose and capabilities mostly align: local Apple Notes search reasonably needs filesystem access and local MCP execution. The main risk is install trust and scope: it asks users to grant Full Disk Access to Bun, then clone and run a personal GitHub repo with unpinned dependencies and no concrete release verification. Data flow is mostly coherent and on-device, with optional cloud synthesis clearly disclosed, so this is not confirmed malicious; it is a medium-high security risk due to broad local access combined with personal-repo execution.
Confidence: 89%Severity: 71%
Audit Metadata