foundation-models-on-device
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The integration patterns described in the skill facilitate the processing of untrusted user input that can subsequently trigger functional application logic through custom tools. 1. Ingestion points: Untrusted data enters the model context via
session.respond(to: prompt)andsession.streamResponse(to: prompt)as documented inSKILL.md. 2. Boundary markers: The provided Swift code examples do not demonstrate the use of delimiters or specific boundary markers to isolate user input from system instructions. 3. Capability inventory: TheToolprotocol (e.g.,RecipeSearchTool) provides a mechanism for the model to execute arbitrary code within the application environment, creating a chain from processed input to execution. 4. Sanitization: The documentation lacks examples of input validation, escaping, or prompt sanitization prior to model invocation.
Audit Metadata