wispr
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the macOS
openutility to interact with the Wispr Flow application via URI schemes. This is a standard method for application control on macOS.\n- [INDIRECT_PROMPT_INJECTION]: Theswitch-micfunctionality provides a surface for command injection by interpolating unvalidated user input into a shell execution context.\n - Ingestion points: The
<PREFIX>parameter inSKILL.mdused for microphone identification.\n - Boundary markers: The URL template uses double quotes, but there are no instructions to the agent to escape shell-sensitive characters (e.g., backticks, semicolons, or dollar signs) before substitution.\n
- Capability inventory: Shell execution capability via the
opencommand.\n - Sanitization: No sanitization, validation, or escaping logic is defined for the interpolated user input.
Audit Metadata