xcode-compilation-analyzer

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/diagnose_compilation.py performs project cleaning and build diagnostic operations using xcodebuild. The script correctly uses subprocess.run with argument lists to mitigate command injection risks.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes project-derived build logs which may contain strings from the source code, presenting a vulnerability surface where malicious code content could influence the agent's analysis or subsequent actions.\n
  • Ingestion points: Output from xcodebuild builds captured and parsed in scripts/diagnose_compilation.py.\n
  • Boundary markers (absent): No delimiters or explicit instructions are provided to ignore embedded instructions in the ingested data.\n
  • Capability inventory: Execution of xcodebuild via subprocess.run in scripts/diagnose_compilation.py.\n
  • Sanitization (present): Log content is parsed using specific regular expressions to isolate timing data and source locations.\n- [EXTERNAL_DOWNLOADS]: The skill references documentation and technical articles from Apple, Bitrise, and the author's blog (avanderlee.com). These are static references for informational purposes and do not involve runtime code execution or script downloads.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 12:24 PM
Security Audit — agent-trust-hub — xcode-compilation-analyzer