Back to skill

Security audit

Drafts CLI

Security checks across malware telemetry and agentic risk

Overview

This skill is a transparent Drafts-for-macOS helper, with ordinary caution needed because it can change notes and run Drafts actions.

Install this only if you use Drafts on macOS and trust the external CLI source. Be explicit about which Drafts note or action you want, and use extra care with replace or run commands because they can overwrite note content or trigger Drafts automations.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill description is broadly worded to trigger on generic note-taking requests such as creating notes, listing drafts, searching drafts, or managing an inbox. That can cause an agent to invoke this skill for routine user intents without sufficiently confirming the target app, environment, or whether modifying Drafts content is appropriate, increasing the chance of unintended access to or modification of user notes.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The documentation advertises prepend, append, replace, and edit operations on existing drafts but does not warn that these commands directly alter user data and may overwrite note contents. In an agent setting, this makes accidental destructive actions more likely, especially because replace can fully discard prior content and actions may be run against an existing draft UUID.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.