macos-accessibility

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill implements security checks using subprocess.run to execute the system codesign utility, ensuring that target applications are authentic before interacting with them.
  • [DATA_EXFILTRATION]: Provides diagnostic utilities to read the macOS TCC (Transparency, Consent, and Control) database at /Library/Application Support/com.apple.TCC/TCC.db. This allows the agent to verify permission status, though the skill notes this requires elevated system permissions such as Full Disk Access.
  • [INDIRECT_PROMPT_INJECTION]: The skill interacts with and retrieves text from third-party application UI elements, which constitutes an attack surface where untrusted content could influence agent actions.
  • Ingestion points: Accesses UI element attributes such as AXTitle, AXValue, and AXSelectedText via the AXUIElementCopyAttributeValue API in SKILL.md and references/advanced-patterns.md.
  • Boundary markers: The skill does not employ explicit boundary delimiters for UI-derived data, although it does define a permission tier model to restrict access to sensitive fields like password attributes.
  • Capability inventory: Possesses capabilities to perform UI actions via AXUIElementPerformAction and execute system-level commands through subprocess.run.
  • Sanitization: Includes a sanitize_ax_value function in references/security-examples.md designed to truncate large inputs and remove null bytes from retrieved strings.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 05:54 PM
Security Audit — agent-trust-hub — macos-accessibility