automating-keynote
Warn
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONPRIVILEGE_ESCALATION
Full Analysis
- [COMMAND_EXECUTION]: The scripts
create_keynote_presentation.pyandexport_keynote_presentation.pyare vulnerable to AppleScript injection. They construct script strings using Python f-strings to interpolate command-line arguments (like presentation titles and file paths) directly into AppleScript code, which is then executed viaosascript. An attacker-controlled title containing double quotes could break out of the string literal and execute arbitrary AppleScript commands, includingdo shell scriptfor shell access. - [DYNAMIC_EXECUTION]: The documentation in
keynote-advanced.mdpromotes a "Bridge Pattern" for chart creation that manually assembles AppleScript strings from JavaScript arrays and executes them viaapp.runScript(). This pattern is inherently unsafe if the input data contains unsanitized double quotes or other control characters, leading to code injection in the AppleScript context. - [INDIRECT_PROMPT_INJECTION]: The
markdown_to_keynote.pyscript ingests and parses external markdown files to generate presentations. This creates a surface for indirect prompt injection where malicious content inside a document could potentially influence the agent's logic or exploit the command execution vulnerabilities during the processing of slide titles and content. - [PRIVILEGE_ESCALATION]: The skill documents the use of GUI scripting via
System Eventsinkeynote-advanced.md. While a legitimate tool for macOS automation when dictionaries are incomplete, GUI scripting requires "Accessibility" permissions and provides the ability to interact with the entire system UI, which represents a significant capability that could be abused if an agent is compromised.
Audit Metadata