yutori-iphone-mirroring
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
uvxcommand to execute theyutori-mcputility, allowing the agent to perform clicks, swipes, and text entry within the iPhone Mirroring window. - [EXTERNAL_DOWNLOADS]: The
uvxcommand fetches theyutori-mcppackage from a remote registry at runtime. As this package is a direct vendor resource from 'yutori-ai', it is considered a functional requirement of the skill. - [INDIRECT_PROMPT_INJECTION]: The skill processes visual content from the iPhone screen, which represents an ingestion point for untrusted data that could potentially contain malicious instructions. Ingestion points: Captures and analyzes visual frames of the 'iPhone Mirroring' application window (SKILL.md). Boundary markers: The instructions provide specific interaction constraints and explicitly forbid the agent from exploring apps or data outside the user's requested task. Capability inventory: The skill can simulate user input and navigate the iPhone interface using the
yutori-mcptool. Sanitization: The instructions direct the agent to avoid sensitive app categories (e.g., banking, health, messages) and advise the user to remove private widgets or notifications before use.
Audit Metadata