apple-design
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is composed exclusively of Markdown instructions and reference documents. It lacks any executable scripts (.js, .py, .sh), package manifests, or configuration files that could facilitate malicious behavior.
- [SAFE]: The skill uses standard instructional language to set the agent's persona as a design reviewer. There are no prompt injection attempts to override safety filters or extract system instructions.
- [SAFE]: No hardcoded credentials, sensitive file paths, or unauthorized network operations were detected. All external links point to official Apple developer documentation or the author's public GitHub repository for reference purposes.
- [INDIRECT_PROMPT_INJECTION]: The skill has an ingestion surface as it is designed to process user-provided screenshots, code, and design specifications. However, the risk is negligible because the skill does not grant the agent any dangerous capabilities (such as file writing, command execution, or network access) that could be exploited by malicious data.
- [SAFE]: No obfuscation techniques, hidden URLs, or persistence mechanisms were found. The '!' character appears in the documentation only within the context of text strings or file tree visualizations, not as dynamic context injection commands.
Audit Metadata