hammerspoon
Warn
Audited by Socket on Jul 24, 2026
1 alert found:
SecuritySecurityREFERENCE.md
MEDIUMSecurityMEDIUM
REFERENCE.md
No clear evidence in the provided fragment of direct malware behavior (no obfuscation, no credentials, and no explicit network exfiltration/persistence). However, it includes high-risk local automation primitives—especially reading clipboard contents and typing them as keystrokes into the focused application, plus Chrome URL/title enumeration and tab control, and the ability to change system/power/network settings. Treat the overall package as high-privilege automation requiring strict trust, access control, and permission review of any triggers that could cause sensitive data handling or automated input injection.
Confidence: 62%Severity: 74%
Audit Metadata