callkit
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONMETADATA_POISONINGEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from VoIP push payloads which are used to populate system call interfaces and network requests without sanitization.
- Ingestion points: The
didReceiveIncomingVoIPPushWithanddidReceiveIncomingPushWithmethods in thePushManagerclass withinSKILL.mdingest data directly from thePKPushPayloaddictionary provided by the system. - Boundary markers: There are no markers or instructions provided to distinguish the untrusted payload data from valid system instructions, which could allow a malicious payload to influence the agent's behavior.
- Capability inventory: The skill utilizes the
provider.reportNewIncomingCallmethod (found inSKILL.md) to modify system-level UI and thesendTokenToServermethod to transmit data to an external server. - Sanitization: The implementation directly extracts and uses values such as "handle" and "callerName" from the payload dictionary without any validation, escaping, or length checks before passing them to system APIs.
- [METADATA_POISONING]: The skill contains deceptive and hallucinated technical information, referencing non-existent versions of iOS and non-existent framework classes.
- Evidence: Multiple references to "iOS 26" and "iOS 26.4" appear throughout
SKILL.mdandreferences/callkit-patterns.md. It includes specific implementation details and API availability annotations (@available(iOS 26.4, *)) for these fictional versions, which may mislead an agent or user into generating invalid code. - [EXTERNAL_DOWNLOADS]: The skill references technical documentation on an unverified and suspicious external domain.
- Evidence: The References section of
SKILL.mdpoints to multiple resources athttps://sosumi.ai/documentation/callkit, which is not an official or recognized technical vendor for iOS development documentation.
Audit Metadata