Drafts CLI

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward Drafts-for-macOS helper that clearly tells the agent how to read and change Drafts notes, with no evidence of hidden or unrelated behavior.

Install only if you use Drafts on macOS and trust the external GitHub CLI. Consider pinning or reviewing the CLI before installing, and be careful with commands that replace note contents or run Drafts actions because they can permanently change your Drafts data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The skill description is broad enough that an agent could invoke it for generic note-taking requests without first confirming the required macOS/Drafts context. That can lead to unintended command execution attempts against a local Drafts instance, including creating or modifying notes, when a safer or more appropriate tool should have been used.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The command documentation shows destructive and side-effecting operations like replace, append, prepend, edit, and run actions, but the skill lacks an explicit safety warning that these commands can change note contents or trigger Drafts automations. In an agent setting, that omission increases the chance of silent state changes or action execution without adequate confirmation from the user.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal