macos-accessibility
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill implements security checks using
subprocess.runto execute the systemcodesignutility, ensuring that target applications are authentic before interacting with them. - [DATA_EXFILTRATION]: Provides diagnostic utilities to read the macOS TCC (Transparency, Consent, and Control) database at
/Library/Application Support/com.apple.TCC/TCC.db. This allows the agent to verify permission status, though the skill notes this requires elevated system permissions such as Full Disk Access. - [INDIRECT_PROMPT_INJECTION]: The skill interacts with and retrieves text from third-party application UI elements, which constitutes an attack surface where untrusted content could influence agent actions.
- Ingestion points: Accesses UI element attributes such as
AXTitle,AXValue, andAXSelectedTextvia theAXUIElementCopyAttributeValueAPI inSKILL.mdandreferences/advanced-patterns.md. - Boundary markers: The skill does not employ explicit boundary delimiters for UI-derived data, although it does define a permission tier model to restrict access to sensitive fields like password attributes.
- Capability inventory: Possesses capabilities to perform UI actions via
AXUIElementPerformActionand execute system-level commands throughsubprocess.run. - Sanitization: Includes a
sanitize_ax_valuefunction inreferences/security-examples.mddesigned to truncate large inputs and remove null bytes from retrieved strings.
Audit Metadata