sensorkit

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references documentation and implementation guides hosted on an unofficial third-party domain (sosumi.ai) rather than the official Apple Developer portal. These links are used for core framework components, including SRSensorReader, SRSensor, and entitlement configurations in SKILL.md.
  • [DATA_EXFILTRATION]: The skill facilitates access to and processing of highly sensitive user information, including keyboard typing metrics (which can track sentiment and typing speed), speech audio/recognition results, and clinical health data such as ECG and PPG.
  • [INDIRECT_PROMPT_INJECTION]: The skill establishes an attack surface for indirect prompt injection due to the nature of the data it processes.
  • Ingestion points: Data is ingested from system sensors via SRSensorReader as described in SKILL.md and references/sensorkit-patterns.md.
  • Boundary markers: No delimiters or instructions to ignore embedded commands are present in the code snippets provided for processing keyboard or speech recognition data.
  • Capability inventory: The skill provides logic for fetching, iterating, and logging diverse user samples across multiple high-privilege sensors.
  • Sanitization: There is no evidence of data sanitization, filtering, or validation for transcribed speech or keyboard metrics before the data is processed or logged in the provided Swift examples.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:17 AM
Security Audit — agent-trust-hub — sensorkit