Back to skill

Security audit

iCloud Find My

Security checks for vulnerabilities and agentic risk

Overview

The skill is openly about using iCloud Find My, but it handles highly sensitive family location data with unsafe parsing and weak consent/storage boundaries.

Review before installing. Use this only for devices and family members who have consented, avoid proactive tracking unless explicitly desired, do not store the Apple ID in ordinary workspace files, and replace eval-based parsing with a safe parser such as JSON parsing or ast.literal_eval with validation. Pin and review the pyicloud version if using automated installation.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:116
Finding

Arbitrary Code Execution Through Unsafe Evaluation of Location Data

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:14
Finding

Unpinned Third-Party Package Installation

Content
View full analysis
Remediation
View remediation
`. - Pin or constrain important transitive dependencies through a reviewed lock file where the installation workflow permits it. - Verify downloaded artifacts using trusted hashes or signed release artifacts. - Document the expected package registry, upstream repository, publisher, and reviewed version. - Configure automated dependency monitoring, but require review and testing before updating the pinned version. - Avoid silently installing the newest release during Skill setup. - Apply equivalent version controls to installation commands in both the setup documentation and the Skill metadata. ]]>

T09 · Insecure Skill Coding Practices

Note
Location
SKILL.md:29
Finding

Plaintext Persistence of Apple ID in the Agent Workspace

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The documentation explicitly recommends using eval() to parse the Location field, which treats CLI output as executable Python code rather than untrusted data. If the output is malformed, spoofed, or attacker-controlled at any point in the pipeline, this can lead to arbitrary code execution completely outside the skill’s stated purpose of reading Find My data.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
100% confidence
Finding

The example shell pipeline feeds command output directly into python3 -c and calls eval(sys.stdin.read()), creating a concrete arbitrary code execution path. In a skill context, this is especially dangerous because it normalizes unsafe data handling and could cause the agent to execute attacker-influenced content while performing a routine location lookup.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README explicitly instructs the agent to store the user's Apple ID in its workspace, which creates a persistent credential-handling risk without clear safeguards, minimization, or warnings. Even if this is only an identifier and not a password, Apple IDs are sensitive account identifiers that can be exposed through logs, workspace sync, backups, or later prompt/context leakage.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs storing the user’s Apple ID in TOOLS.md or workspace config for future use without any warning about sensitivity, retention, or access scope. While an Apple ID is not a password, it is still sensitive account metadata that can enable profiling, phishing, account correlation, or unintended disclosure through logs, sync, or repository sharing.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill is designed to retrieve precise device and family-member location and battery data, but it provides no privacy warning, consent requirement, or usage boundary. Because location data is highly sensitive and the skill targets family devices, the absence of safeguards materially increases the risk of covert tracking, misuse, and over-collection.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The proactive use cases encourage continuous monitoring, presence inference, and behavioral conclusions such as home/away detection and low-battery alerts without any discussion of consent or surveillance risk. This moves the skill from ad hoc user-requested lookup into ongoing tracking and inference, which is significantly more privacy-invasive and easier to abuse.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Telling an agent to persist a user's Apple ID in its workspace introduces unnecessary retention of sensitive user data in a location that may be accessible to other tools, logs, backups, or future agent tasks. In this skill's context, the risk is heightened because the same workflow also deals with long-lived iCloud sessions and family-device location data, so compromise of retained identifiers can increase privacy exposure and facilitate broader account targeting.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instructions direct the agent to retain the user’s Apple ID in persistent configuration for future use, increasing the lifetime and exposure surface of sensitive account information. In agent environments, persistent docs/config can be read by other skills, included in backups, synced externally, or leaked via prompt/context reuse.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The proactive use cases instruct the agent to reuse location data to answer unrelated queries and infer whether the user is at home, which is a form of secondary use beyond a direct Find My lookup. This broadens the skill into ambient surveillance and behavioral inference, making misuse more likely and increasing harm if the data is accessed without clear, current user intent.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.