automating-contacts

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides a script scripts/import_contacts_from_csv.py that processes external CSV files to populate the macOS Contacts database. This creates a surface for indirect prompt injection where malicious data in the source file could be imported into the system. Ingestion points: The import_contacts_from_csv.py script reads data from a user-specified CSV file path. Boundary markers: The script lacks explicit boundary markers or warnings to the agent to ignore instructions embedded within the CSV data. Capability inventory: The skill utilizes the PyXA library for deep integration with macOS apps and mentions the use of doShellScript for executing shell commands in references/contacts-advanced.md. Sanitization: No sanitization or validation of the CSV field content is performed before the data is pushed to the Contacts application.
  • [COMMAND_EXECUTION]: The documentation in references/contacts-advanced.md recommends using doShellScript as a fallback mechanism for tasks the standard dictionary cannot handle. This allows the execution of arbitrary shell commands from within the automation scripts, which could be leveraged if the input to these scripts is compromised.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 02:25 PM