clipboard

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted conversational data to copy it to the clipboard, presenting a potential injection surface.
  • Ingestion points: Conversational text blocks enter the agent environment dynamically within SKILL.md via heredocs.
  • Boundary markers: Present. Instructions explicitly mandate single-quoted heredocs ('CLIPBOARD', 'CLIPBOARD_HTML', 'CLIPBOARD_TEXT') to encapsulate text blocks.
  • Capability inventory: Local shell command execution (cat, pbcopy, rm, swift) and temporary file writing (/tmp/) in SKILL.md.
  • Sanitization: Present. Single-quoted heredoc delimiters ensure that the shell treats the input entirely as a literal string, completely neutralizing command substitution or variable expansion vectors.
  • [COMMAND_EXECUTION]: Executes local commands including cat, pbcopy, and rm. These invocations use static syntax structures and avoid passing user text as command-line arguments.
  • [DYNAMIC_EXECUTION]: Invokes swift -e to process clipboard operations using native macOS APIs. The Swift payload is hardcoded and interprets user input strictly as data from temporary text/HTML files rather than executing it.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 04:08 AM
Security Audit — agent-trust-hub — clipboard