Security audit
Pushman
Security checks for vulnerabilities and agentic risk
Overview
This skill is a clearly scoped Pushman helper for sending and inspecting the user's own iPhone notifications, with explicit safeguards around sends, credentials, and private history.
Install this only if you intend agents to use your local Pushman setup. Notification sends are visible and quota-consuming, and device/history data is private, so use explicit wording for sends, targets, and credential changes.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
