shortcuts-generator
Fail
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: CRITICALINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides documentation for building shortcuts that process external input and interact with AI models (
is.workflow.actions.askllm).\n - Ingestion points: The
is.workflow.actions.askaction (found inACTIONS.mdandEXAMPLES.md) allows shortcuts to ingest untrusted user input.\n - Boundary markers: The provided XML templates (e.g., Example 3 and 5 in
EXAMPLES.md) demonstrate passing variables directly to AI prompts without using boundary delimiters or explicit safety instructions.\n - Capability inventory: The Shortcuts platform documented in
ACTIONS.mdsupports actions for network operations (is.workflow.actions.downloadurl), file system access (is.workflow.actions.documentpicker.save), and script execution.\n - Sanitization: The reference documentation lacks examples or guidance for sanitizing user-supplied data before processing.\n- [COMMAND_EXECUTION]: The skill catalogs powerful system actions such as
is.workflow.actions.runshellscript,is.workflow.actions.runsshscript, andis.workflow.actions.runosascript(documented inACTIONS.md), which allow generated shortcuts to execute arbitrary commands on the target system.\n- [DYNAMIC_EXECUTION]: The skill instructs the agent on generating.shortcutfiles from XML templates, which are signed and executed by the system (described inSKILL.mdandEXAMPLES.md), representing the creation and execution of scripted workflows.\n- [OBFUSCATION]: The documentation uses the Object Replacement Characterextensively acrossSKILL.md,EXAMPLES.md,VARIABLES.md, andPARAMETER_TYPES.md. The skill explicitly identifies this character as the required placeholder for variable serialization in the Apple Shortcuts format, clarifying that it is a functional requirement and not a concealment technique.
Recommendations
- CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
Audit Metadata