wield
Warn
Audited by Socket on Jul 27, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill is largely aligned with its stated macOS automation purpose and primarily relies on Apple's built-in osascript, with no direct evidence of credential harvesting or third-party proxying. However, it grants broad desktop-control capability, can trigger real-world actions across Mail/Finder/System Events/Terminal, and supports unattended or hook-based automation; this footprint is powerful enough to warrant medium risk despite the documented safety guardrails.
Confidence: 84%Severity: 58%
Audit Metadata