automating-contacts
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides a script
scripts/import_contacts_from_csv.pythat processes external CSV files to populate the macOS Contacts database. This creates a surface for indirect prompt injection where malicious data in the source file could be imported into the system. Ingestion points: Theimport_contacts_from_csv.pyscript reads data from a user-specified CSV file path. Boundary markers: The script lacks explicit boundary markers or warnings to the agent to ignore instructions embedded within the CSV data. Capability inventory: The skill utilizes thePyXAlibrary for deep integration with macOS apps and mentions the use ofdoShellScriptfor executing shell commands inreferences/contacts-advanced.md. Sanitization: No sanitization or validation of the CSV field content is performed before the data is pushed to the Contacts application. - [COMMAND_EXECUTION]: The documentation in
references/contacts-advanced.mdrecommends usingdoShellScriptas a fallback mechanism for tasks the standard dictionary cannot handle. This allows the execution of arbitrary shell commands from within the automation scripts, which could be leveraged if the input to these scripts is compromised.
Audit Metadata