app-store-review

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill instructs the agent to fetch documentation and guidelines from external sources, including the third-party domain sosumi.ai. This domain is used to provide required-reason API documentation but is not a whitelisted or trusted vendor domain, representing a network operation to an external reference site.\n- [INDIRECT_PROMPT_INJECTION]: The skill is designed to audit untrusted application source code, metadata, and configuration files (such as PrivacyInfo.xcprivacy and Info.plist) for App Store compliance.\n
  • Ingestion points: The agent ingests user-provided application source code, property lists, and privacy manifests during the audit process (e.g., in references/review-checklists.md).\n
  • Boundary markers: The skill does not define clear delimiters or provide instructions for the agent to ignore embedded instructions within the ingested application files.\n
  • Capability inventory: The skill involves file reading and network fetching capabilities, and references the use of distribution tools like xcodebuild, altool, and Transporter for the submission workflow.\n
  • Sanitization: No explicit sanitization or validation of the ingested application content is specified before processing by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 10:35 PM
Security Audit — agent-trust-hub — app-store-review