applescript

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes osascript and Python's subprocess module to execute scripts and shell commands for macOS system automation. It proactively includes filtering logic to block dangerous shell patterns and administrative privilege requests.
  • [DYNAMIC_EXECUTION]: The skill features a script caching mechanism that uses osacompile to generate and execute binary script files (.scpt) at runtime from dynamically generated source code.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user input to interpolate values into script templates, creating a potential attack surface if the recommended sanitization logic is not strictly followed.
  • Ingestion points: Untrusted strings are ingested and interpolated into script templates within the SafeScriptBuilder class in SKILL.md and the build_safe_script function in references/security-examples.md.
  • Boundary markers: The skill enforces the use of the quoted form of AppleScript property and manual character escaping to isolate user-provided data from command logic.
  • Capability inventory: Provides extensive application control and shell command execution capabilities via do shell script and osascript.
  • Sanitization: Includes implementation of regex-based application name validation and automated escaping of double quotes and backslashes in user strings.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 05:54 PM
Security Audit — agent-trust-hub — applescript