Context-Inappropriate Capability
Medium
- Confidence
- 94% confidence
- Finding
- The documented calendar helper executes local AppleScript through osascript, which is a state-changing capability on the host and can modify user calendar data. Although the sample appears intended for convenience rather than abuse, it normalizes shelling out to a powerful local automation interface without clear trust boundaries, input validation, or an explicit warning that it will create persistent local events.
