axiom-audit-core-data
Pass
Audited by Gen Agent Trust Hub on Apr 26, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill defines a comprehensive technical audit process for detecting legitimate Core Data bugs, such as thread-confinement violations, migration safety risks, and data loss patterns.
- [PROMPT_INJECTION]: The skill contains an indirect prompt injection surface due to its processing of untrusted local data. 1. Ingestion points: Swift source files and data model definition files (.swift, .xcdatamodeld). 2. Boundary markers: No delimiters or instructions are used to isolate untrusted content from the auditing logic. 3. Capability inventory: The skill relies on file system discovery and reading tools; it lacks high-privilege capabilities such as network access or shell execution. 4. Sanitization: No sanitization of the findings or source code is performed during the audit process.
Audit Metadata