applescript — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited applescript (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Expert in AppleScript and JavaScript for Automation (JXA) for macOS system scripting.
# AppleScript one-liner
osascript -e 'tell application "Finder" to activate'
# AppleScript file
osascript script.scpt
# JXA (JavaScript for Automation)
osascript -l JavaScript -e 'Application("Finder").activate()'
# Multi-line AppleScript
osascript <<'EOF'
tell application "Safari"
make new document
set URL of document 1 to "https://example.com"
end tell
EOF-- Activate app
tell application "Safari" to activate
-- Get frontmost app
tell application "System Events" to get name of first process whose frontmost is true
-- List windows
tell application "System Events"
tell process "Safari"
get name of every window
end tell
end tell
-- Click UI elements
tell application "System Events"
tell process "Safari"
click button 1 of window 1
end tell
end tell-- Open file
tell application "Finder"
open file "Macintosh HD:Users:user:file.txt"
end tell
-- Get selected files
tell application "Finder"
get selection as alias list
end tell
-- Create folder
tell application "Finder"
make new folder at desktop with properties {name:"New Folder"}
end tell-- Display notification
display notification "Task complete" with title "Script" sound name "default"
-- Dialog with buttons
display dialog "Continue?" buttons {"Cancel", "OK"} default button "OK"
-- Choose file
choose file with prompt "Select a file:"
-- Choose folder
choose folder with prompt "Select a folder:"-- Run shell command (use quoted form for safety!)
set userPath to "/path/with spaces"
do shell script "ls " & quoted form of userPath
-- Get command output
set result to do shell script "date '+%Y-%m-%d'"
-- Run with timeout
with timeout of 10 seconds
do shell script "long-running-command"
end timeout// Activate app
Application('Safari').activate()
// Get frontmost app
Application('System Events').processes.whose({ frontmost: true })[0].name()
// Display dialog
const app = Application.currentApplication()
app.includeStandardAdditions = true
app.displayDialog('Hello!', { buttons: ['OK'], defaultButton: 'OK' })
// Run shell command
app.doShellScript('ls -la')
// Work with files
const finder = Application('Finder')
const desktop = finder.desktop
finder.make({ new: 'folder', at: desktop, withProperties: { name: 'Test' } })ALWAYS use `quoted form of` for shell arguments:
-- BAD: injection risk
do shell script "echo " & userInput
-- GOOD: safe
do shell script "echo " & quoted form of userInputNEVER execute with administrator privileges unless explicitly requested:
-- Requires user confirmation and password
do shell script "..." with administrator privilegesASK user before accessing these sensitive apps:
ASK user before these high-risk operations:
keystroke command)NEVER do these without explicit user request:
keystroke passwords or sensitive data# Check if app is scriptable
sdef /Applications/Safari.app | head -50
# Open Script Editor dictionary
open -a "Script Editor" /Applications/Safari.app
# Test script interactively
osascript -i| Issue | Solution |
|---|---|
| "Not authorized" | Grant permissions in System Preferences → Privacy → Automation |
| "Application not found" | Use exact app name from /Applications |
| "Can't get window 1" | App may have no windows open |
| Timeout | Use with timeout of N seconds block |
| Quotes in strings | Escape with \" or use quoted form of |
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.