cryptotokenkit

Warn

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: MEDIUMPRIVILEGE_ESCALATIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
  • [PRIVILEGE_ESCALATION]: The skill documentation instructs the use of sudo to register app extensions at the system level (sudo -u _securityagent /Applications/TokenHost.app/Contents/MacOS/TokenHost). This guides the agent to perform or recommend administrative actions that bypass normal user permissions.
  • [EXTERNAL_DOWNLOADS]: All external documentation links point to a third-party domain (sosumi.ai) rather than official platform sources. This forces the agent to rely on potentially untrusted or malicious external content for technical implementation details.
  • [METADATA_POISONING]: The skill contains deceptive technical claims, such as support for 'iOS/iPadOS 26+' and 'Swift 6.3', which are versions that do not currently exist. This metadata poisoning could lead an agent to attempt to use non-existent APIs or follow inaccurate security guidelines tailored for a fictional environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits a significant attack surface for indirect prompt injection from hardware tokens:
  • Ingestion points: The skill processes data directly from external smart card readers and NFC sessions (e.g., TKSmartCard.send, readPIVObject, extractCertificate in SKILL.md and references/cryptotokenkit-patterns.md).
  • Boundary markers: There are no explicit instructions to treat data from the smart card as untrusted or to validate its content beyond basic structure.
  • Capability inventory: The skill provides functionality to write to the system keychain, perform cryptographic signing/decryption, and modify token configuration data.
  • Sanitization: While the skill uses TLV parsing, it passes raw binary data from external sources into sensitive system APIs like SecCertificateCreateWithData and SecKey operations without thorough validation.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 14, 2026, 03:42 PM
Security Audit — agent-trust-hub — cryptotokenkit