shortcuts-generator

Fail

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: CRITICALINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides documentation for building shortcuts that process external input and interact with AI models (is.workflow.actions.askllm).\n
  • Ingestion points: The is.workflow.actions.ask action (found in ACTIONS.md and EXAMPLES.md) allows shortcuts to ingest untrusted user input.\n
  • Boundary markers: The provided XML templates (e.g., Example 3 and 5 in EXAMPLES.md) demonstrate passing variables directly to AI prompts without using boundary delimiters or explicit safety instructions.\n
  • Capability inventory: The Shortcuts platform documented in ACTIONS.md supports actions for network operations (is.workflow.actions.downloadurl), file system access (is.workflow.actions.documentpicker.save), and script execution.\n
  • Sanitization: The reference documentation lacks examples or guidance for sanitizing user-supplied data before processing.\n- [COMMAND_EXECUTION]: The skill catalogs powerful system actions such as is.workflow.actions.runshellscript, is.workflow.actions.runsshscript, and is.workflow.actions.runosascript (documented in ACTIONS.md), which allow generated shortcuts to execute arbitrary commands on the target system.\n- [DYNAMIC_EXECUTION]: The skill instructs the agent on generating .shortcut files from XML templates, which are signed and executed by the system (described in SKILL.md and EXAMPLES.md), representing the creation and execution of scripted workflows.\n- [OBFUSCATION]: The documentation uses the Object Replacement Character  extensively across SKILL.md, EXAMPLES.md, VARIABLES.md, and PARAMETER_TYPES.md. The skill explicitly identifies this character as the required placeholder for variable serialization in the Apple Shortcuts format, clarifying that it is a functional requirement and not a concealment technique.
Recommendations
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 27, 2026, 03:07 PM
Security Audit — agent-trust-hub — shortcuts-generator