browserenginekit
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides educational content and implementation patterns for the BrowserEngineKit framework on iOS and iPadOS. It covers the necessary architectural components and system integration steps required for building alternative browser engines.
- [SAFE]: Instructions regarding entitlements (such as
com.apple.developer.web-browser-engine.host) and system eligibility checks (BEAvailability) accurately reflect the framework's requirements and follow security guidelines for region-locked features. - [SAFE]: The skill explicitly advocates for security mitigations, including the application of restricted sandboxing (
applyRestrictedSandbox), implementation of hardware memory tagging for specific regions, and the use of witnessed APIs for JIT memory transitions to prevent exploitation. - [SAFE]: The documented architectural patterns for XPC communication between the host app and its extension processes (networking, rendering, and web content) correctly follow the principle of least privilege and secure process isolation.
- [SAFE]: All external references provided for further reading point to documentation resources related to the framework and do not involve suspicious downloads or remote code execution.
Audit Metadata