spm-build-analysis

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The helper script scripts/check_spm_pins.py executes shell commands based on data parsed from the local environment.
  • Evidence: The script uses subprocess.run(["git", "ls-remote", "--tags", url], ...) where url is extracted from the project.pbxproj file using a regular expression.
  • Risk: Lack of argument validation allows for flag injection. If a malicious project.pbxproj file defines a repositoryURL starting with a hyphen (e.g., --upload-pack), it could trigger unexpected behavior or arbitrary command execution when the script is run.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted project files which can influence its behavior and the commands it executes.
  • Ingestion points: scripts/check_spm_pins.py reads and parses project.pbxproj from the project directory.
  • Boundary markers: None. The script processes extracted strings without verifying their safety or origin.
  • Capability inventory: The skill has the capability to execute git commands via subprocess.run with parameters derived from the ingested data.
  • Sanitization: There is no sanitization or prefix-checking (e.g., ensuring the URL starts with https:// or git@) to prevent argument injection attacks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 03:00 PM