remote-mac

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides templates and instructions for the agent to execute shell commands on remote systems using SSH (e.g., ssh -o RequestTTY=no -o RemoteCommand=none HOST 'COMMAND'). It also covers managing background services with launchctl and tmux sessions.\n- [DATA_EXFILTRATION]: The skill exposes internal network details, including Tailscale internal IP addresses (100.93.99.79, 100.118.219.64) and a public IP address (131.143.4.3). It also references specific file paths on the local system used for tracking node inventory (/Users/steipete/Projects/manager/computers.yaml, agents.yaml).\n- [INDIRECT_PROMPT_INJECTION]: The skill is designed to take user input regarding specific machines and perform operations on them. This creates an attack surface where maliciously crafted user input could potentially influence the commands executed via SSH, particularly if the agent does not strictly validate hostnames against the provided topology before execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 11:27 PM
Security Audit — agent-trust-hub — remote-mac