coreml

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill demonstrates best practices for Core ML integration, including asynchronous model loading and efficient caching of compiled models in the Application Support directory to optimize performance. The documentation links point to sosumi.ai, which is a common community reference domain.
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion and processing of external machine learning models, creating a vulnerability surface for potentially untrusted data.
  • Ingestion points: External models are ingested through MLModel.load(contentsOf:) and MLModel.compileModel(at:) as seen in SKILL.md and references/coreml-swift-integration.md.
  • Boundary markers: None implemented in the Swift snippets.
  • Capability inventory: The skill includes file system write access for model caching and mentions loading models from remote servers.
  • Sanitization: The code does not perform integrity validation or source verification for model assets before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 03:41 PM
Security Audit — agent-trust-hub — coreml