hammerspoon

Warn

Audited by Socket on Jul 24, 2026

1 alert found:

Security
SecurityMEDIUM
REFERENCE.md

No clear evidence in the provided fragment of direct malware behavior (no obfuscation, no credentials, and no explicit network exfiltration/persistence). However, it includes high-risk local automation primitives—especially reading clipboard contents and typing them as keystrokes into the focused application, plus Chrome URL/title enumeration and tab control, and the ability to change system/power/network settings. Treat the overall package as high-privilege automation requiring strict trust, access control, and permission review of any triggers that could cause sensitive data handling or automated input injection.

Confidence: 62%Severity: 74%
Audit Metadata
Analyzed At
Jul 24, 2026, 01:39 AM
Package URL
pkg:socket/skills-sh/wilbeibi%2Fwilbeibi-skills%2Fhammerspoon%2F@80f0443d8f1c023d0112b9bf1bb3895782d25536c9e730c46495382afbdf59a2
Security Audit — socket — hammerspoon