device-integrity

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill directs users and agents to a non-official, third-party domain (sosumi.ai) for all external documentation and security verification algorithms.
  • Numerous links across SKILL.md and references/device-integrity-patterns.md point to https://sosumi.ai/documentation/... instead of the expected https://developer.apple.com/....
  • Using a non-standard domain for security-critical implementation guidance (e.g., attestation-object-validation-guide) is a best-practice violation and could lead to the provision of modified or untrustworthy security instructions.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process binary data generated by remote devices, creating an attack surface for indirect prompt injection.
  • Ingestion points: The server-side verification logic in SKILL.md and references/device-integrity-patterns.md handles device_token, attestation, and assertion data objects provided by external app instances.
  • Boundary markers: The skill relies on cryptographic validation (SHA256, CBOR) but does not provide specific prompt delimiters or instructions for the agent to treat this ingested data as untrusted when processing related logic.
  • Capability inventory: The skill utilizes URLSession for network communication and the system Keychain for persistent storage of key identifiers (SKILL.md).
  • Sanitization: The skill provides robust implementation patterns for cryptographic sanitization, including SHA256 hashing, signature verification, and certificate chain validation (references/device-integrity-patterns.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 06:50 AM
Security Audit — agent-trust-hub — device-integrity