apple-reminders

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of the remindctl utility through a third-party Homebrew tap (steipete/tap/remindctl) if the tool is not already present on the system.
  • [COMMAND_EXECUTION]: The skill makes extensive use of the os.shell.run tool to interact with the macOS operating system, including software installation via brew, privacy authorization via remindctl authorize, and opening system preferences.
  • [PROMPT_INJECTION]: The skill has an indirect prompt injection surface because it ingests untrusted user data (e.g., reminder titles, list names, and dates) and interpolates this data into shell command arguments.
  • Ingestion points: User-provided strings for reminder creation and management in SKILL.md.
  • Boundary markers: The instructions explicitly state: "Always confirm reminder content, list, and due date with the user before creating or completing."
  • Capability inventory: Uses os.shell.run for all operations.
  • Sanitization: The skill uses an arguments array for shell execution which provides some protection, but relies on the underlying tool implementation for full sanitization.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 05:53 PM
Security Audit — agent-trust-hub — apple-reminders