apple-notes

Pass

Audited by Gen Agent Trust Hub on Jul 9, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTIONNO_CODE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions for installing the 'memo' CLI tool from a third-party repository (antoniorodr/memo) using the Homebrew package manager or pip.
  • [COMMAND_EXECUTION]: The agent executes the 'memo' command-line utility to perform administrative actions on Apple Notes, including listing, searching, creating, and modifying notes.
  • [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface as it ingests untrusted data from note content. 1. Ingestion Points: Reading note content into the agent's context. 2. Boundary Markers: None specified to separate content from instructions. 3. Capability Inventory: Modification and deletion of notes. 4. Sanitization: No sanitization is performed on note content before it is processed.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 9, 2026, 10:45 PM
Security Audit — agent-trust-hub — apple-notes