app-store-audit
Pass
Audited by Gen Agent Trust Hub on Aug 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data from iOS application projects to perform its audit functions.
- Ingestion points: The skill reads various files within an iOS project, including Info.plist, source code, and configuration files, to identify permission strings, SDK usage, and network settings (SKILL.md).
- Boundary markers: The instructions do not specify the use of delimiters or boundary markers to distinguish between the project data being analyzed and the agent's internal instructions.
- Capability inventory: The skill generates comprehensive audit reports, suggested code diffs, and prompts for the user to execute. It does not contain instructions for network operations or unauthorized file modifications (SKILL.md).
- Sanitization: The skill does not mention specific sanitization or filtering logic for the content it ingests from the project files before processing them for the final report.
Audit Metadata