apple-notes
Pass
Audited by Gen Agent Trust Hub on Aug 1, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTIONNO_CODE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires the installation of the
memoCLI tool from a personal Homebrew tap (antoniorodr/memo/memo) and GitHub repository (github.com/antoniorodr/memo). - [COMMAND_EXECUTION]: The skill utilizes the
memocommand-line tool to interact with the system's Apple Notes application, involving shell command execution for data retrieval and modification. - [PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection as it ingests and processes untrusted data from Apple Notes content. * Ingestion points: Content from existing notes, user-provided note titles, and search queries. * Boundary markers: None identified. * Capability inventory: Local command execution via the
memotool. * Sanitization: None specified for external content. - [NO_CODE]: The skill consists solely of a
SKILL.mdfile containing instructions and metadata, without accompanying script files.
Audit Metadata