apple-music

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The script apple-music.sh executes AppleScript via osascript using user-supplied inputs such as song and playlist names without escaping. This creates a potential for AppleScript injection if malicious strings are provided as arguments.
  • Evidence: Direct interpolation of variables $target and $query into AppleScript strings in apple-music.sh (e.g., lines 440 and 456).
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external search queries and track names, presenting a surface for indirect prompt injection if an agent processes untrusted data and passes it to the music control commands.
  • Ingestion points: Command-line arguments in apple-music.sh (e.g., cmd_player, cmd_search).
  • Boundary markers: Absent.
  • Capability inventory: Local command execution via osascript, file system read/write for configuration, and network access via curl to Apple APIs.
  • Sanitization: Absent; input strings are not sanitized before being used in AppleScript commands or API requests.
  • [EXTERNAL_DOWNLOADS]: The skill references official resources from Apple for authorization and API interaction.
  • Evidence: auth.html loads the MusicKit library from a well-known Apple CDN, and apple-music.sh makes requests to Apple's official Music API.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 04:06 AM
Security Audit — agent-trust-hub — apple-music