apollo-ios
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill includes a data ingestion surface through the fetching of external GraphQL schemas and release tags.
- Ingestion points: GraphQL schemas are retrieved via the
apollo-ios-cli fetch-schematool andschemaDownloadconfiguration (SKILL.md, references/setup.md); release tags are retrieved from a remote Git repository (scripts/list-apollo-ios-versions.sh). - Boundary markers: The SKILL.md file contains a dedicated "Untrusted content" section that explicitly instructs the agent to treat fetched data as non-executable and to ignore any directives found within.
- Capability inventory: The skill uses Bash for CLI operations and Git, and file manipulation tools (Read, Write, Edit) to manage generated Swift code and configurations (SKILL.md, references/setup.md, references/codegen.md).
- Sanitization: The skill employs instructional sanitization by providing specific guidelines to disregard prompt injection attempts within external data.
- [EXTERNAL_DOWNLOADS]: The skill references downloads from trusted vendor repositories.
- Fetches the
apollo-ios-clibinary from the official Apollo GraphQL GitHub releases page (references/setup.md). - Retrieves version metadata from the official
apollographql/apollo-iosGitHub repository (scripts/list-apollo-ios-versions.sh).
Audit Metadata