apple-music
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The script
apple-music.shexecutes AppleScript viaosascriptusing user-supplied inputs such as song and playlist names without escaping. This creates a potential for AppleScript injection if malicious strings are provided as arguments. - Evidence: Direct interpolation of variables
$targetand$queryinto AppleScript strings inapple-music.sh(e.g., lines 440 and 456). - [INDIRECT_PROMPT_INJECTION]: The skill processes external search queries and track names, presenting a surface for indirect prompt injection if an agent processes untrusted data and passes it to the music control commands.
- Ingestion points: Command-line arguments in
apple-music.sh(e.g.,cmd_player,cmd_search). - Boundary markers: Absent.
- Capability inventory: Local command execution via
osascript, file system read/write for configuration, and network access viacurlto Apple APIs. - Sanitization: Absent; input strings are not sanitized before being used in AppleScript commands or API requests.
- [EXTERNAL_DOWNLOADS]: The skill references official resources from Apple for authorization and API interaction.
- Evidence:
auth.htmlloads the MusicKit library from a well-known Apple CDN, andapple-music.shmakes requests to Apple's official Music API.
Audit Metadata