ipsw
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill requires the agent to analyze and interpret data from untrusted external files, which could contain adversarial instructions designed to influence the agent's logic.
- Ingestion points: The agent processes external data via commands like
ipsw macho info,ipsw symbolicate,ipsw dyld disass, andipsw sb decacross all reference files and the main skill body. - Boundary markers: The instructions do not define specific delimiters or warnings for the agent to ignore potentially malicious strings embedded within binary metadata, symbols, or log files.
- Capability inventory: The skill utilizes the
ipswCLI to perform deep file system analysis, header generation (class-dump), and remote firmware extraction. - Sanitization: There is no evidence of sanitization or validation of the content extracted from binaries before it is presented to the agent for interpretation.
- [COMMAND_EXECUTION]: The skill is centered around the execution of the
ipswcommand-line utility to perform reverse engineering tasks. - Numerous examples in
SKILL.mdand thereferences/directory illustrate the execution of shell commands for kernel analysis, dylib extraction, and symbolication. - [EXTERNAL_DOWNLOADS]: The documentation references external resources for tool installation and data acquisition.
- The skill suggests installing the
ipswtool via the vendor's Homebrew tap (blacktop/tap/ipsw). - Reference documentation (
references/download.md) includes patterns for downloading official firmware components from Apple's content delivery network (updates.cdn-apple.com). - These downloads are associated with legitimate vendor infrastructure or well-known, trusted services.
Audit Metadata