clipboard
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted conversational data to copy it to the clipboard, presenting a potential injection surface.
- Ingestion points: Conversational text blocks enter the agent environment dynamically within
SKILL.mdvia heredocs. - Boundary markers: Present. Instructions explicitly mandate single-quoted heredocs (
'CLIPBOARD','CLIPBOARD_HTML','CLIPBOARD_TEXT') to encapsulate text blocks. - Capability inventory: Local shell command execution (
cat,pbcopy,rm,swift) and temporary file writing (/tmp/) inSKILL.md. - Sanitization: Present. Single-quoted heredoc delimiters ensure that the shell treats the input entirely as a literal string, completely neutralizing command substitution or variable expansion vectors.
- [COMMAND_EXECUTION]: Executes local commands including
cat,pbcopy, andrm. These invocations use static syntax structures and avoid passing user text as command-line arguments. - [DYNAMIC_EXECUTION]: Invokes
swift -eto process clipboard operations using native macOS APIs. The Swift payload is hardcoded and interprets user input strictly as data from temporary text/HTML files rather than executing it.
Audit Metadata