foundation-models-on-device

Pass

Audited by Gen Agent Trust Hub on Apr 1, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill contains architectural patterns and Swift code snippets for building on-device AI features. All operations described are local to the device, prioritizing user privacy and offline functionality.
  • [SAFE]: No suspicious network activity, hardcoded credentials, or obfuscated content were detected. The skill focuses on using official or projected system frameworks for generative AI tasks.
  • [DATA_EXPOSURE_EXFILTRATION]: No sensitive file access or unauthorized data transmission patterns are present. The documentation explicitly emphasizes that no data leaves the device.
  • [INDIRECT_PROMPT_INJECTION]: The skill describes patterns for processing untrusted user input via LanguageModelSession.respond(to:) and provides a mechanism for tool calling (e.g., RecipeSearchTool). It mitigates common risks by recommending structured output via the @Generable macro and the use of explicit system instructions to guide model behavior and safety.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 1, 2026, 11:09 AM
Security Audit — agent-trust-hub — foundation-models-on-device