sensorkit
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references documentation and implementation guides hosted on an unofficial third-party domain (
sosumi.ai) rather than the official Apple Developer portal. These links are used for core framework components, includingSRSensorReader,SRSensor, and entitlement configurations inSKILL.md. - [DATA_EXFILTRATION]: The skill facilitates access to and processing of highly sensitive user information, including keyboard typing metrics (which can track sentiment and typing speed), speech audio/recognition results, and clinical health data such as ECG and PPG.
- [INDIRECT_PROMPT_INJECTION]: The skill establishes an attack surface for indirect prompt injection due to the nature of the data it processes.
- Ingestion points: Data is ingested from system sensors via
SRSensorReaderas described inSKILL.mdandreferences/sensorkit-patterns.md. - Boundary markers: No delimiters or instructions to ignore embedded commands are present in the code snippets provided for processing keyboard or speech recognition data.
- Capability inventory: The skill provides logic for fetching, iterating, and logging diverse user samples across multiple high-privilege sensors.
- Sanitization: There is no evidence of data sanitization, filtering, or validation for transcribed speech or keyboard metrics before the data is processed or logged in the provided Swift examples.
Audit Metadata