apollo-ios

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill includes a data ingestion surface through the fetching of external GraphQL schemas and release tags.
  • Ingestion points: GraphQL schemas are retrieved via the apollo-ios-cli fetch-schema tool and schemaDownload configuration (SKILL.md, references/setup.md); release tags are retrieved from a remote Git repository (scripts/list-apollo-ios-versions.sh).
  • Boundary markers: The SKILL.md file contains a dedicated "Untrusted content" section that explicitly instructs the agent to treat fetched data as non-executable and to ignore any directives found within.
  • Capability inventory: The skill uses Bash for CLI operations and Git, and file manipulation tools (Read, Write, Edit) to manage generated Swift code and configurations (SKILL.md, references/setup.md, references/codegen.md).
  • Sanitization: The skill employs instructional sanitization by providing specific guidelines to disregard prompt injection attempts within external data.
  • [EXTERNAL_DOWNLOADS]: The skill references downloads from trusted vendor repositories.
  • Fetches the apollo-ios-cli binary from the official Apollo GraphQL GitHub releases page (references/setup.md).
  • Retrieves version metadata from the official apollographql/apollo-ios GitHub repository (scripts/list-apollo-ios-versions.sh).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:50 PM
Security Audit — agent-trust-hub — apollo-ios