skills/bastos/skills/apple-cktool-js/Gen Agent Trust Hub

apple-cktool-js

Pass

Audited by Gen Agent Trust Hub on Aug 7, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [SAFE]: The skill follows security best practices for managing CloudKit credentials, environment variables, and CI secrets. It explicitly warns against anti-patterns such as committing sensitive files or bundling management tokens in client-side code.
  • [EXTERNAL_DOWNLOADS]: The skill references official Apple documentation, GitHub repositories, and scoped npm packages (@apple/cktool.*). These resources originate from a well-known and trusted organization.
  • [SAFE]: The skill includes patterns for processing external CloudKit schema files and record data, establishing a risk surface for indirect prompt injection. However, it incorporates significant guardrails, including instructions to validate schemas before import, explicit environment checks for destructive actions, and guidance on redacting sensitive diagnostic logs. (Ingestion points: .ckdb schema files and API record responses; Capability inventory: Network requests and file system writes).
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 7, 2026, 07:57 PM
Security Audit — agent-trust-hub — apple-cktool-js