Is joargp/accli safe?
Yes. joargp/accli is safe to install. Oathe's behavioral security audit gave the accli skill by joargp a trust score of 91/100 with 4 findings, none critical or high.
https://github.com/openclaw/skills/tree/main/skills/joargp/accli
Is joargp/accli safe to install?
The accli skill provides legitimate Apple Calendar CLI functionality through well-documented commands and workflows. While it requires external npm package installation which introduces some risk, the skill itself contains no malicious code and implements appropriate user consent mechanisms.
What security issues were found in joargp/accli?
Category Scores
Findings (4)
MEDIUM External npm package dependency -15 ▶
The skill requires installation of an external npm package '@joargp/accli' which could introduce security risks if the package is compromised
LOW Calendar manipulation potential -10 ▶
The skill enables creation, modification, and deletion of calendar events which could be misused to manipulate user schedules, though this requires explicit user consent
LOW System file access during installation -10 ▶
System processes accessed sensitive files (.env, SSH keys, AWS credentials) during installation, though no exfiltration occurred
LOW JavaScript for Automation dependency -5 ▶
The tool relies on macOS JavaScript for Automation which involves code execution, though this is documented and expected behavior
Should I install joargp/accli?
Oathe's verdict for joargp/accli is SAFE with a trust score of 91/100. Recommendation: Install.