T09 · Insecure Skill Coding Practices
- Location
SKILL.md:116- Finding
Arbitrary Code Execution Through Unsafe Evaluation of Location Data
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is openly about using iCloud Find My, but it handles highly sensitive family location data with unsafe parsing and weak consent/storage boundaries.
Review before installing. Use this only for devices and family members who have consented, avoid proactive tracking unless explicitly desired, do not store the Apple ID in ordinary workspace files, and replace eval-based parsing with a safe parser such as JSON parsing or ast.literal_eval with validation. Pin and review the pyicloud version if using automated installation.
SKILL.md:116Arbitrary Code Execution Through Unsafe Evaluation of Location Data
SKILL.md:14Unpinned Third-Party Package Installation
SKILL.md:29Plaintext Persistence of Apple ID in the Agent Workspace
The documentation explicitly recommends using eval() to parse the Location field, which treats CLI output as executable Python code rather than untrusted data. If the output is malformed, spoofed, or attacker-controlled at any point in the pipeline, this can lead to arbitrary code execution completely outside the skill’s stated purpose of reading Find My data.
The example shell pipeline feeds command output directly into python3 -c and calls eval(sys.stdin.read()), creating a concrete arbitrary code execution path. In a skill context, this is especially dangerous because it normalizes unsafe data handling and could cause the agent to execute attacker-influenced content while performing a routine location lookup.
The README explicitly instructs the agent to store the user's Apple ID in its workspace, which creates a persistent credential-handling risk without clear safeguards, minimization, or warnings. Even if this is only an identifier and not a password, Apple IDs are sensitive account identifiers that can be exposed through logs, workspace sync, backups, or later prompt/context leakage.
The skill instructs storing the user’s Apple ID in TOOLS.md or workspace config for future use without any warning about sensitivity, retention, or access scope. While an Apple ID is not a password, it is still sensitive account metadata that can enable profiling, phishing, account correlation, or unintended disclosure through logs, sync, or repository sharing.
The skill is designed to retrieve precise device and family-member location and battery data, but it provides no privacy warning, consent requirement, or usage boundary. Because location data is highly sensitive and the skill targets family devices, the absence of safeguards materially increases the risk of covert tracking, misuse, and over-collection.
The proactive use cases encourage continuous monitoring, presence inference, and behavioral conclusions such as home/away detection and low-battery alerts without any discussion of consent or surveillance risk. This moves the skill from ad hoc user-requested lookup into ongoing tracking and inference, which is significantly more privacy-invasive and easier to abuse.
Telling an agent to persist a user's Apple ID in its workspace introduces unnecessary retention of sensitive user data in a location that may be accessible to other tools, logs, backups, or future agent tasks. In this skill's context, the risk is heightened because the same workflow also deals with long-lived iCloud sessions and family-device location data, so compromise of retained identifiers can increase privacy exposure and facilitate broader account targeting.
The instructions direct the agent to retain the user’s Apple ID in persistent configuration for future use, increasing the lifetime and exposure surface of sensitive account information. In agent environments, persistent docs/config can be read by other skills, included in backups, synced externally, or leaked via prompt/context reuse.
The proactive use cases instruct the agent to reuse location data to answer unrelated queries and infer whether the user is at home, which is a form of secondary use beyond a direct Find My lookup. This broadens the skill into ambient surveillance and behavioral inference, making misuse more likely and increasing harm if the data is accessed without clear, current user intent.
No suspicious patterns detected.