utm
Pass
Audited by Gen Agent Trust Hub on Aug 30, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill invokes a wide range of macOS system utilities to manage VM lifecycles and disk images. This includes
osascriptfor AppleScript automation,utmctlfor CLI operations,hdiutilfor mounting and creating disk images,rsyncfor file synchronization, andwimlib-imagexfor WIM manipulation. It also usesncandsshfor network verification and guest access. - [INDIRECT_PROMPT_INJECTION]: The skill processes data originating from guest virtual machines through commands like
utmctl exec,utmctl file pull, and AppleScript'sexecute vmfunction. This creates an attack surface where a compromised or malicious guest VM could provide output containing instructions intended to manipulate the host agent's behavior. - Ingestion points:
utmctl exec,utmctl ip-address,utmctl file pull, and AppleScriptexecutecommand results. - Boundary markers: No specific delimiters or "ignore instructions" warnings are defined for processing guest output.
- Capability inventory: The skill possesses file writing (
utmctl file push), arbitrary command execution on the host (osascript), and network operations. - Sanitization: No explicit sanitization or validation of guest-provided data is mentioned.
- [DYNAMIC_EXECUTION]: The skill uses dynamic execution patterns to perform system-level tasks. Specifically, it employs
osascript -efor ad-hoc AppleScript execution and pipes inline scripts topython3to modifyconfig.plistfiles, which are used to bypass limitations in the standard AppleScript dictionary for UTM. - [DATA_EXPOSURE]: The instructions direct the agent to read local application configuration files (e.g., UTM's
config.plist) and system files like/var/db/dhcpd_leasesto retrieve VM details and IP addresses. It also references~/.ssh/id_ed25519within documentation examples for configuring SSH access to guests.
Audit Metadata