ios-marketing-capture
Warn
Audited by Socket on Apr 23, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. Most capabilities align with an iOS screenshot automation skill, and the local build/simctl/flutter flows are proportionate. The main concerns are the optional third-party AppLaunchFlow MCP path: it installs external tooling through unpinned `npx`, expands the agent's trust boundary, and uploads screenshots to a non-Apple service. This is not fundamentally incompatible with the skill's purpose, but it raises medium security risk and warrants user scrutiny before enabling the MCP workflow.
Confidence: 81%Severity: 58%
Audit Metadata