macos-process-injection

Warn

Audited by Gen Agent Trust Hub on Jul 21, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill includes an 'AI LOAD INSTRUCTION' that attempts to set an 'expert' persona for the agent. This is a technique used to influence model behavior and potentially override default safety considerations by framing the agent as a specialized security tool with fewer constraints.
  • [COMMAND_EXECUTION]: The skill provides numerous functional shell commands for auditing the local system, searching for vulnerable binaries, and executing payloads. This includes using 'codesign' to check for entitlements and 'gcc' to compile malicious dynamic libraries on the fly.
  • [REMOTE_CODE_EXECUTION]: The skill contains technical walkthroughs and source code (C, Objective-C, and Python) to achieve remote code execution via process injection. Examples include the use of 'task_for_pid' to write to process memory, 'DYLD_INSERT_LIBRARIES' for environment variable injection, and exploiting the Chrome DevTools Protocol to execute code in Electron applications.
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install third-party packages from official registries (NPM) to facilitate exploitation, specifically tools for manipulating Electron application archives.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 21, 2026, 01:23 PM
Security Audit — agent-trust-hub — macos-process-injection