metrickit

Warn

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: MEDIUMMETADATA_POISONINGINDIRECT_PROMPT_INJECTION
Full Analysis
  • [METADATA_POISONING]: The skill provides technical instructions for non-existent versions of Apple's operating systems, specifically "iOS 27" and "iPadOS 27," and references future events such as "WWDC26." This deceptive framing may mislead users and AI agents into adopting hallucinated or invalid technical specifications.
  • [METADATA_POISONING]: The skill directs users to https://sosumi.ai for what it claims to be official Apple documentation. Providing unofficial, third-party links for sensitive telemetry and diagnostic reporting information creates a risk of misdirection to untrusted sources.
  • [INDIRECT_PROMPT_INJECTION]: The skill establishes a workflow for processing external system telemetry and diagnostic reports which could potentially contain attacker-controlled data.
  • Ingestion points: The MetricManager.metricReports and MetricManager.diagnosticReports sequences in SKILL.md and references/metrickit-patterns.md ingest external data into the application environment.
  • Boundary markers: No boundary markers or "ignore embedded instruction" warnings are provided for the incoming report data.
  • Capability inventory: The skill itself does not implement active network or file-writing capabilities but provides structural guidance for implementing a "durable outbox" and an upload worker to handle this data.
  • Sanitization: No sanitization or validation logic is proposed for the raw diagnostic payloads, which include potentially variable content like CallStackTree reason and exception fields.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 14, 2026, 03:42 PM
Security Audit — agent-trust-hub — metrickit