skills/clerk/skills/clerk-swift/Gen Agent Trust Hub

clerk-swift

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONPRIVILEGE_ESCALATION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill explicitly instructs the agent to wire the Clerk publishable key directly into the application configuration and advises against using indirection methods like environment variables or build settings, which is a deviation from secret management best practices even for frontend keys.
  • [INDIRECT_PROMPT_INJECTION]: The skill workflow involves retrieving a remote markdown file from a URL found in the project's README and following its instructions to configure the project, creating a vulnerability surface.
  • Ingestion points: Remote documentation URLs sourced from the installed package's README file.
  • Boundary markers: None; the skill does not specify markers to distinguish instructions from data in the fetched content.
  • Capability inventory: The skill allows modification of project source files, installation of dependencies, and addition of application capabilities/entitlements.
  • Sanitization: None; the agent does not validate or sanitize the remote content before interpreting and applying its setup steps.
  • [PRIVILEGE_ESCALATION]: The skill automates the modification of application entitlements, specifically the 'Associated Domains' capability, which changes the security boundaries and permissions of the iOS application.
  • [EXTERNAL_DOWNLOADS]: The skill utilizes the WebFetch tool to retrieve environment configuration and documentation from vendor-controlled domains (clerk.com).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 11:40 AM
Security Audit — agent-trust-hub — clerk-swift