Back to skill

Security audit

AirDrop

Security checks for vulnerabilities and agentic risk

Overview

This AirDrop skill is mostly coherent, but its optional Shortcut mode can run any named local macOS Shortcut and is broader than a simple AirDrop helper.

Review this before installing if you plan to use Shortcut mode. Direct mode opens the native AirDrop chooser for explicit local files, but Shortcut mode trusts the named macOS Shortcut and whatever actions that Shortcut contains. Use only shortcuts you created or audited, keep sensitive-file confirmations enabled, and avoid broad activation preferences if you do not want file-transfer behavior triggered by vague sharing requests.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The security manifest materially understates behavior: in --shortcut mode the script delegates control to any user-specified macOS Shortcut, which may read, write, execute apps, or perform network actions. In an agent/tooling context, inaccurate manifests can mislead policy engines or reviewers into granting this skill broader trust than its runtime behavior warrants.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The exposed interface advertises an AirDrop sender but also offers a generic Shortcut execution path, expanding capability well beyond the stated purpose. In a security-sensitive agent environment, this kind of capability mismatch is dangerous because callers may invoke the skill assuming only local AirDrop behavior while actually enabling arbitrary automation flows.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code allows execution of any installed Shortcut by name and passes attacker-controlled file inputs into it. Because macOS Shortcuts can trigger wide-ranging side effects such as file operations, application control, shell actions, and network access, this creates a broad automation primitive that is substantially more dangerous than an AirDrop helper, especially if an agent can be induced to call it.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The activation rule is broad enough to trigger on generic requests about sharing or handing off files to Apple devices, which can cause the skill to activate in situations the user did not explicitly intend. In a file-transfer skill, unintended activation matters because it can steer the assistant toward local file handling, preference capture, and transfer preparation based on ambiguous phrasing, increasing the chance of privacy mistakes or accidental disclosure.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The instruction to "Start naturally" is coupled with the entire file being written as mandatory English interaction guidance, with no indication that the user may choose another language or locale. Under the policy, forcing a specific language without opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.