appkit-accessibility-auditor
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill defines a narrow, technical role for accessibility auditing with explicit instructions to avoid unnecessary changes or architectural refactors.
- [EXTERNAL_DOWNLOADS]: The skill references official Apple documentation and Human Interface Guidelines from 'developer.apple.com'. These are trusted, well-known resources for macOS development and do not involve executable code downloads.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process user-provided AppKit code (e.g., NSView, NSTableView).
- Ingestion points: User-provided code snippets or screen descriptions in the prompt.
- Boundary markers: None explicitly defined to separate untrusted code from instructions.
- Capability inventory: The skill's output is restricted to text-based findings and code patches. It does not utilize tools for network access, file system modifications, or shell execution.
- Sanitization: The instructions do not specify sanitization for the input code, but the lack of high-privilege capabilities mitigates the risk of injection-based attacks.
Audit Metadata