ssh-gui

Warn

Audited by Socket on Sep 17, 2026

1 alert found:

Security
SecurityMEDIUM
bin/ssh-gui

The code is a legitimate SSH-based macOS GUI automation utility and shows no clear malicious payload or covert data theft. It contains two significant command-injection vulnerabilities: direct interpolation of the screenshot region and unsafe interpolation of SSH_GUI_AX_TIMEOUT into a remote shell command. The arbitrary AppleScript interface is intentionally powerful and should be restricted to trusted users. Shell-escape or validate all interpolated values, especially region and timeout, before use.

Confidence: 98%Severity: 82%
Audit Metadata
Analyzed At
Sep 17, 2026, 02:21 PM
Package URL
pkg:socket/skills-sh/vesely%2Fskills%2Fssh-gui%2F@43c8b9e2b9a520109188152df99e88704b3a350ff6729d4bf19281801b56ab04
Security Audit — socket — ssh-gui