T09 · Insecure Skill Coding Practices
- Location
scripts/playlist_create.py:31- Finding
Arbitrary AppleScript Injection Through Unsanitized Playlist Name
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly does what it says, but it ships an under-disclosed playlist script with an AppleScript injection risk that could let crafted input run unintended local automation.
Review this skill before installing. The playback automation is expected for its purpose, but it needs Accessibility and Automation permissions and can send music searches to Apple. Avoid using the bundled playlist_create.py script with untrusted playlist names until its AppleScript handling is fixed or removed.
scripts/playlist_create.py:31Arbitrary AppleScript Injection Through Unsanitized Playlist Name
The script programmatically sends keypresses to the Music app via osascript/System Events after opening a music:// URL, causing UI-driven actions without explicit user consent at execution time. This can trigger unintended playback or interact with the focused Music UI state in ways the user did not anticipate, which is especially risky in an agent skill context where actions may run non-interactively.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
def run(cmd):
return subprocess.run(cmd, text=True, capture_output=True)
def current_track():
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
def run(cmd):
return subprocess.run(cmd, text=True, capture_output=True)
def current_track():
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
def run(cmd):
return subprocess.run(cmd, text=True, capture_output=True)
def current_track():
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
def run(cmd):
return subprocess.run(cmd, text=True, capture_output=True)
def current_track():
The script sends user-supplied search terms to Apple's iTunes search API without any disclosure, confirmation, or privacy notice. This can expose potentially sensitive user interests or internal project names to a third party, which is risky in an agent skill context where users may not expect outbound network access.
The script automates Music.app and System Events to create playlists, open external links, and simulate keystrokes that modify the user's library without an explicit confirmation step. In an agent setting, UI scripting and application automation are sensitive because they can trigger unintended actions on the host and train users to accept opaque automation touching local apps.
The user's query is transmitted to Apple's iTunes Search API without any notice, which creates an information disclosure/privacy issue. While the destination is expected and the data is limited to the search term, the lack of disclosure is still relevant for a skill that may process user-provided content automatically.
No suspicious patterns detected.