foundation-models-on-device

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The integration patterns described in the skill facilitate the processing of untrusted user input that can subsequently trigger functional application logic through custom tools. 1. Ingestion points: Untrusted data enters the model context via session.respond(to: prompt) and session.streamResponse(to: prompt) as documented in SKILL.md. 2. Boundary markers: The provided Swift code examples do not demonstrate the use of delimiters or specific boundary markers to isolate user input from system instructions. 3. Capability inventory: The Tool protocol (e.g., RecipeSearchTool) provides a mechanism for the model to execute arbitrary code within the application environment, creating a chain from processed input to execution. 4. Sanitization: The documentation lacks examples of input validation, escaping, or prompt sanitization prior to model invocation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 02:39 AM
Security Audit — agent-trust-hub — foundation-models-on-device