skills/firecrawl/openclaw/apple-notes/Gen Agent Trust Hub

apple-notes

Warn

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of a third-party CLI tool memo from a Homebrew tap (antoniorodr/memo/memo) that is not associated with a trusted vendor. It also suggests a manual installation method using pip install .. \n- [COMMAND_EXECUTION]: The skill relies on executing various shell commands through the memo binary to manage macOS Apple Notes, including creating, editing, and deleting entries. \n- [INDIRECT_PROMPT_INJECTION]: \n
  • Ingestion points: Reads existing Apple Notes content and processes search queries provided by the user. \n
  • Boundary markers: None identified; the skill does not specify delimiters to separate note content from instructions. \n
  • Capability inventory: Includes shell command execution through the memo tool and file system writes during note exports to HTML or Markdown. \n
  • Sanitization: No explicit sanitization or validation of external note content is mentioned before it is processed by the agent or CLI tool.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 17, 2026, 07:54 PM
Security Audit — agent-trust-hub — apple-notes