apple-reminders
Pass
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of the
remindctlutility through a third-party Homebrew tap (steipete/tap/remindctl) if the tool is not already present on the system. - [COMMAND_EXECUTION]: The skill makes extensive use of the
os.shell.runtool to interact with the macOS operating system, including software installation viabrew, privacy authorization viaremindctl authorize, and opening system preferences. - [PROMPT_INJECTION]: The skill has an indirect prompt injection surface because it ingests untrusted user data (e.g., reminder titles, list names, and dates) and interpolates this data into shell command arguments.
- Ingestion points: User-provided strings for reminder creation and management in
SKILL.md. - Boundary markers: The instructions explicitly state: "Always confirm reminder content, list, and due date with the user before creating or completing."
- Capability inventory: Uses
os.shell.runfor all operations. - Sanitization: The skill uses an arguments array for shell execution which provides some protection, but relies on the underlying tool implementation for full sanitization.
Audit Metadata