core-data-expert

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFE
Full Analysis

The security analysis of the Core Data Expert skill did not reveal any malicious patterns or significant vulnerabilities. The skill's primary function is to provide educational content and code examples for developers working with iOS and macOS database persistence.

  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to collect user-provided error logs and stack traces as part of its triage process. This represents a potential surface for indirect prompt injection if malicious instructions are embedded within the logs. However, since the skill does not grant the agent access to sensitive tools or the ability to execute commands, the practical risk is negligible.
  • [EXTERNAL_DOWNLOADS]: The skill includes references to external educational resources, such as the author's GitHub repository and a concurrency course. These links are contextually appropriate for a technical guidance skill and originate from the vendor's known infrastructure.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 02:59 PM
Security Audit — agent-trust-hub — core-data-expert