maintaining-macos-health
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONPERSISTENCEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSPRIVILEGE_ESCALATIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill frequently uses shell commands via
subprocess.runandos.systemfor administrative tasks such as disk measurements, process monitoring, and executing cleanup operations. These are protected by a validation layer inapply-cleanup-selection.pyanddisk_safety.pythat blacklists sensitive system roots (/System, /bin, etc.) and user credential directories. - [PERSISTENCE]: The skill installs a macOS LaunchAgent (
com.local.mac-health-check.plist) to provide active background monitoring. This is a standard and transparent implementation for the skill's stated purpose of proactive health alerting. - [INDIRECT_PROMPT_INJECTION]: The skill ingests file metadata (filenames and paths) which could contain malicious instructions. It mitigates this risk by using a restricted 'metadata-only' runner for the AI agent, explicitly instructing it to ignore instructions embedded in filenames, and requiring a human reviewer to approve any cleanup plan through a separate interface.
- [DYNAMIC_EXECUTION]: Runtime execution is used to apply user-selected cleanup commands and to open the local browser interface. The
apply-cleanup-selection.pyscript restricts these commands to a specific whitelist (rm, brew, docker, etc.) and enforces strict path validation to prevent arbitrary execution. - [EXTERNAL_DOWNLOADS]: The skill uses
ntfy.shfor push notifications andHomebrewto install required utilities likealerterandMole. These are well-known services and are used exclusively for the skill's documented monitoring and maintenance functions. - [PRIVILEGE_ESCALATION]: While the skill uses
sudofor cleaning certain system logs (Tier 6), the targets are restricted to a vetted allowlist of diagnostic and power logs, preventing unauthorized modification of critical system state.
Audit Metadata