skills/blacktop/ipsw-skill/ipsw/Gen Agent Trust Hub

ipsw

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill requires the agent to analyze and interpret data from untrusted external files, which could contain adversarial instructions designed to influence the agent's logic.
  • Ingestion points: The agent processes external data via commands like ipsw macho info, ipsw symbolicate, ipsw dyld disass, and ipsw sb dec across all reference files and the main skill body.
  • Boundary markers: The instructions do not define specific delimiters or warnings for the agent to ignore potentially malicious strings embedded within binary metadata, symbols, or log files.
  • Capability inventory: The skill utilizes the ipsw CLI to perform deep file system analysis, header generation (class-dump), and remote firmware extraction.
  • Sanitization: There is no evidence of sanitization or validation of the content extracted from binaries before it is presented to the agent for interpretation.
  • [COMMAND_EXECUTION]: The skill is centered around the execution of the ipsw command-line utility to perform reverse engineering tasks.
  • Numerous examples in SKILL.md and the references/ directory illustrate the execution of shell commands for kernel analysis, dylib extraction, and symbolication.
  • [EXTERNAL_DOWNLOADS]: The documentation references external resources for tool installation and data acquisition.
  • The skill suggests installing the ipsw tool via the vendor's Homebrew tap (blacktop/tap/ipsw).
  • Reference documentation (references/download.md) includes patterns for downloading official firmware components from Apple's content delivery network (updates.cdn-apple.com).
  • These downloads are associated with legitimate vendor infrastructure or well-known, trusted services.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 02:31 AM
Security Audit — agent-trust-hub — ipsw