cryptotokenkit
Warn
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: MEDIUMPRIVILEGE_ESCALATIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
- [PRIVILEGE_ESCALATION]: The skill documentation instructs the use of
sudoto register app extensions at the system level (sudo -u _securityagent /Applications/TokenHost.app/Contents/MacOS/TokenHost). This guides the agent to perform or recommend administrative actions that bypass normal user permissions. - [EXTERNAL_DOWNLOADS]: All external documentation links point to a third-party domain (
sosumi.ai) rather than official platform sources. This forces the agent to rely on potentially untrusted or malicious external content for technical implementation details. - [METADATA_POISONING]: The skill contains deceptive technical claims, such as support for 'iOS/iPadOS 26+' and 'Swift 6.3', which are versions that do not currently exist. This metadata poisoning could lead an agent to attempt to use non-existent APIs or follow inaccurate security guidelines tailored for a fictional environment.
- [INDIRECT_PROMPT_INJECTION]: The skill exhibits a significant attack surface for indirect prompt injection from hardware tokens:
- Ingestion points: The skill processes data directly from external smart card readers and NFC sessions (e.g.,
TKSmartCard.send,readPIVObject,extractCertificatein SKILL.md and references/cryptotokenkit-patterns.md). - Boundary markers: There are no explicit instructions to treat data from the smart card as untrusted or to validate its content beyond basic structure.
- Capability inventory: The skill provides functionality to write to the system keychain, perform cryptographic signing/decryption, and modify token configuration data.
- Sanitization: While the skill uses TLV parsing, it passes raw binary data from external sources into sensitive system APIs like
SecCertificateCreateWithDataandSecKeyoperations without thorough validation.
Audit Metadata