findmy
Warn
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONPERSISTENCEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill makes extensive use of
osascript(AppleScript) to control the system UI, interact with the Find My application, and manipulate window focus. - Evidence: Commands like
osascript -e 'tell application "FindMy" to activate'and complex UI interactions targetingSystem Eventsto click specific buttons. - [DATA_EXFILTRATION]: Captures and processes highly sensitive location data, including physical addresses and coordinates of all devices and AirTags associated with the user's iCloud account.
- Evidence: Screenshots of the Find My UI are captured via
screencaptureto/tmp/findmy.pngand then passed tovision_analyzeto extract coordinates and addresses. - [PERSISTENCE]: Instructions explicitly suggest establishing persistence via
cronto monitor device movement over time. - Evidence: Rule 3 states: "For ongoing tracking, use a cronjob to periodically capture and log locations."
- [EXTERNAL_DOWNLOADS]: Recommends the installation of a third-party UI automation tool from an external Homebrew tap.
- Evidence: Suggests
brew install steipete/tap/peekaboofor enhanced automation capabilities. - [INDIRECT_PROMPT_INJECTION]: The skill creates a vulnerability surface by processing untrusted UI content (like device names) through a vision model which could contain malicious instructions.
- Ingestion points:
vision_analyzeprocesses screenshots of the Find My app (/tmp/findmy.png). - Boundary markers: Absent. There are no instructions to the vision model to ignore potential text-based injections within the UI image.
- Capability inventory: The skill can execute shell commands (
osascript,screencapture), write to/tmp, and use third-party tools likepeekaboo. - Sanitization: None. The raw output of the vision analysis is used to determine device locations and routes.
Audit Metadata