core-bluetooth
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill contains standard implementation patterns for the Core Bluetooth framework. The provided Swift code is consistent with official platform guidelines for BLE communication.
- [INDIRECT_PROMPT_INJECTION]: The skill implements logic to ingest and process data from external Bluetooth Low Energy peripherals.
- Ingestion points: Untrusted binary data enters the application through
CBPeripheralDelegatecallbacks, specifically via thecharacteristic.valueproperty inSKILL.mdandreferences/ble-patterns.md. - Boundary markers: There are no explicit instructions for the AI to ignore embedded content within the ingested Bluetooth data, although the application logic expects specific binary GATT profile formats.
- Capability inventory: The code snippets are limited to state management and console logging (
print). There are no capabilities for network operations, file system modifications, or arbitrary command execution that could be exploited via malicious Bluetooth data. - Sanitization: The provided patterns utilize strict binary parsing (e.g., extracting specific bits for heart rate flags or mapping bytes to battery levels), which effectively validates the input against the expected data structure.
Audit Metadata