Back to skill

Security audit

Apple Notes

Security checks across malware telemetry and agentic risk

Overview

This skill transparently lets an agent manage Apple Notes on macOS, but users should understand it can read, change, export, and delete private notes once granted access.

Install only if you trust the external memo CLI and want an agent to manage Apple Notes. Grant Notes.app Automation access only when needed, revoke it later if unused, and confirm the exact target before delete, move, edit, or export actions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill documents a destructive delete operation without warning about permanence, safeguards, or expected confirmation behavior. In an agent-driven context, this increases the risk of accidental data loss because a user or downstream agent may invoke deletion without understanding whether recovery is possible.

Missing User Warnings

Low
Confidence
84% confidence
Finding
The skill tells users to grant Automation access to Notes.app but does not explain the privacy implications of that permission. Because Notes can contain sensitive personal or business data, omitting that warning may cause users to over-grant access without understanding the exposure created by the tool or any agent using it.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal