apple-notes
Pass
Audited by Gen Agent Trust Hub on Apr 29, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Recommends manual installation of the
memoutility from a third-party Homebrew tap (antoniorodr/memo). While the source is external, it is a documented prerequisite for the skill's functionality.\n- [COMMAND_EXECUTION]: Uses thememoCLI to perform note-taking operations. The commands are scoped to thememotool's capabilities and do not involve shell injection or elevated privileges.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes content from Apple Notes, which is external data.\n - Ingestion points: Retrieves note content via
memo notes(SKILL.md).\n - Boundary markers: None present; the skill treats note content as standard text input.\n
- Capability inventory: Capabilities are limited to managing notes via the
memoCLI utility (SKILL.md).\n - Sanitization: No explicit sanitization of note content is defined within the skill instructions.
Audit Metadata