metal-shader-expert

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEOBFUSCATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [OBFUSCATION]: The file reference.md uses HTML entities (<, >) to represent comparison operators and template brackets in Metal Shading Language (MSL) code samples.
  • Evidence: Code snippets such as texture2d<float> and logic like i < debug_count use escaped characters. While likely a result of markdown rendering, these encodings can be used to obfuscate intent. The decoded content is legitimate MSL syntax.
  • [INDIRECT_PROMPT_INJECTION]: The skill is configured to use web-research tools (WebFetch, Firecrawl) to ingest external papers and documentation, which could contain malicious instructions.
  • Ingestion points: External content fetched via WebFetch and mcp__firecrawl__firecrawl_search (SKILL.md).
  • Boundary markers: Absent; no instructions provided to the agent to delimit or ignore instructions in fetched data.
  • Capability inventory: The skill can modify the file system (Write, Edit) and execute specialized shell commands for Metal compilation (xcrun, metal, metallib).
  • Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 07:08 PM
Security Audit — agent-trust-hub — metal-shader-expert