spm-build-analysis
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The helper script
scripts/check_spm_pins.pyexecutes shell commands based on data parsed from the local environment. - Evidence: The script uses
subprocess.run(["git", "ls-remote", "--tags", url], ...)whereurlis extracted from theproject.pbxprojfile using a regular expression. - Risk: Lack of argument validation allows for flag injection. If a malicious
project.pbxprojfile defines arepositoryURLstarting with a hyphen (e.g.,--upload-pack), it could trigger unexpected behavior or arbitrary command execution when the script is run. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted project files which can influence its behavior and the commands it executes.
- Ingestion points:
scripts/check_spm_pins.pyreads and parsesproject.pbxprojfrom the project directory. - Boundary markers: None. The script processes extracted strings without verifying their safety or origin.
- Capability inventory: The skill has the capability to execute
gitcommands viasubprocess.runwith parameters derived from the ingested data. - Sanitization: There is no sanitization or prefix-checking (e.g., ensuring the URL starts with
https://orgit@) to prevent argument injection attacks.
Audit Metadata