app-store-audit

Pass

Audited by Gen Agent Trust Hub on Aug 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data from iOS application projects to perform its audit functions.
  • Ingestion points: The skill reads various files within an iOS project, including Info.plist, source code, and configuration files, to identify permission strings, SDK usage, and network settings (SKILL.md).
  • Boundary markers: The instructions do not specify the use of delimiters or boundary markers to distinguish between the project data being analyzed and the agent's internal instructions.
  • Capability inventory: The skill generates comprehensive audit reports, suggested code diffs, and prompts for the user to execute. It does not contain instructions for network operations or unauthorized file modifications (SKILL.md).
  • Sanitization: The skill does not mention specific sanitization or filtering logic for the content it ingests from the project files before processing them for the final report.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 30, 2026, 02:56 PM
Security Audit — agent-trust-hub — app-store-audit