apple-music

Warn

Audited by Socket on Sep 19, 2026

1 alert found:

Anomaly
AnomalyLOW
apple-music.sh

The fragment appears to be a legitimate Apple Music CLI and shows no clear malware, credential theft, exfiltration, persistence, or destructive behavior. It has a material AppleScript injection risk because several external or remote strings are embedded into osascript source without escaping, potentially allowing unintended local Music or system actions. API identifiers also lack robust validation, and the library-add JSON body is unused. Inputs should be escaped or passed through safer AppleScript mechanisms, and identifiers should be validated before constructing requests.

Confidence: 97%Severity: 62%
Audit Metadata
Analyzed At
Sep 19, 2026, 04:06 AM
Package URL
pkg:socket/skills-sh/sundial-org%2Fawesome-openclaw-skills%2Fapple-music%2F@b84ae7943f12e13947c62ae9ba6a50cc63111ccb64982bac399054ce28860408
Security Audit — socket — apple-music