skills/nomadamas/katok/katok-send/Gen Agent Trust Hub

katok-send

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONPRIVILEGE_ESCALATIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied content, such as message text and image file paths, which are interpolated into shell commands for the katok CLI tool. This creates a surface for potential injection if the input is not properly handled. * Ingestion points: Message body text (--text) and image file paths (--image) provided by the user during interaction, as described in SKILL.md. * Boundary markers: The instructions do not specify technical delimiters or boundary markers for the user-supplied content, relying instead on natural language instructions for the agent to seek explicit confirmation. * Capability inventory: The skill executes shell commands using katok for UI automation and sips for image format conversion in SKILL.md. * Sanitization: There is no evidence of explicit input sanitization or validation logic to handle potentially malicious characters or commands within the user-provided text.
  • [PRIVILEGE_ESCALATION]: The skill requests and relies on macOS Accessibility permissions to interact with the KakaoTalk user interface. These are sensitive system-level permissions that grant the ability to observe and control other applications. * Evidence: The workflow in SKILL.md includes a readiness check using katok permissions macos --accessibility.
  • [COMMAND_EXECUTION]: The skill's core functionality is built upon the execution of external CLI commands to automate third-party software. * Evidence: The Workflow and Troubleshooting sections of SKILL.md contain multiple examples of shell commands invoking the katok and sips utilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 07:59 AM
Security Audit — agent-trust-hub — katok-send