xcode-compilation-analyzer
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/diagnose_compilation.pyperforms project cleaning and build diagnostic operations usingxcodebuild. The script correctly usessubprocess.runwith argument lists to mitigate command injection risks.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes project-derived build logs which may contain strings from the source code, presenting a vulnerability surface where malicious code content could influence the agent's analysis or subsequent actions.\n - Ingestion points: Output from
xcodebuildbuilds captured and parsed inscripts/diagnose_compilation.py.\n - Boundary markers (absent): No delimiters or explicit instructions are provided to ignore embedded instructions in the ingested data.\n
- Capability inventory: Execution of
xcodebuildviasubprocess.runinscripts/diagnose_compilation.py.\n - Sanitization (present): Log content is parsed using specific regular expressions to isolate timing data and source locations.\n- [EXTERNAL_DOWNLOADS]: The skill references documentation and technical articles from Apple, Bitrise, and the author's blog (
avanderlee.com). These are static references for informational purposes and do not involve runtime code execution or script downloads.
Audit Metadata