background-processing

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides comprehensive documentation and Swift code examples for iOS background processing. It correctly identifies required Info.plist configurations and lifecycle management for various background task types. The code snippets follow standard development practices, including expiration handling and completion reporting.
  • [NO_CODE]: The skill does not include any executable scripts, binaries, or automated commands. All code is provided as static examples within Markdown documentation for educational purposes.
  • [INDIRECT_PROMPT_INJECTION]: The skill documentation outlines methods for ingesting data from external APIs and push notifications, which represents a potential attack surface if the ingested data is later processed by an agent. Evidence: (1) Ingestion points: SKILL.md (fetchLatestFeed) and references/background-task-patterns.md (fetchMessages, refreshConfig). (2) Boundary markers: Absent in code snippets. (3) Capability inventory: File system access via FileManager, network access via URLSession, and database operations via DatabaseManager. (4) Sanitization: Not explicitly addressed in the code examples.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 03:41 PM
Security Audit — agent-trust-hub — background-processing