eventkit

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill documentation and referenced patterns describe standard usage of the Apple EventKit and EventKitUI frameworks. It correctly addresses current iOS privacy requirements, such as granular permission requests for iOS 17 and later, and includes references to documentation at sosumi.ai in a neutral context.- [INDIRECT_PROMPT_INJECTION]: The skill defines patterns for reading data from the device's calendar and reminders, which are user-controllable inputs. (1) Ingestion points: Data enters through event and reminder properties (titles, notes, etc.) when querying the event store in SKILL.md and references/eventkit-patterns.md. (2) Boundary markers: The skill does not provide specific instructions to the agent to treat this data as untrusted or delimiters to separate data from instructions. (3) Capability inventory: The skill's capabilities are limited to EventKit operations and do not include high-risk tools for network communication or shell execution. (4) Sanitization: No text sanitization or validation is implemented for the data retrieved from the event store.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 03:42 PM
Security Audit — agent-trust-hub — eventkit