wield

Warn

Audited by Socket on Jul 27, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is largely aligned with its stated macOS automation purpose and primarily relies on Apple's built-in osascript, with no direct evidence of credential harvesting or third-party proxying. However, it grants broad desktop-control capability, can trigger real-world actions across Mail/Finder/System Events/Terminal, and supports unattended or hook-based automation; this footprint is powerful enough to warrant medium risk despite the documented safety guardrails.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Jul 27, 2026, 01:13 PM
Package URL
pkg:socket/skills-sh/simota%2Fagent-skills%2Fwield%2F@8fc99133155a99e4b0340eca411d06b41a26dd5016c66dae4932fdaf46723518
Security Audit — socket — wield