swift-architecture
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides external documentation links to
sosumi.aifor core Apple technologies (Observation, SwiftUI migration) and the Composable Architecture. - Ingestion points: The
Referencessection inSKILL.mdcontains multiple links tososumi.aiwhich an agent might fetch to expand its architectural knowledge. - Boundary markers: There are no instructions or boundary markers advising the agent to treat the content from these external URLs as untrusted or to ignore embedded instructions.
- Capability inventory: The skill allows the agent to generate and review Swift code architecture, meaning poisoned data from these external sites could directly influence the code and security recommendations provided to the user.
- Sanitization: No validation or sanitization of the content from these external URLs is performed.
- [METADATA_POISONING]: The skill utilizes URLs that mimic official Apple documentation paths (e.g.,
sosumi.ai/documentation/...) but point to a non-official, third-party domain. This is potentially deceptive as it encourages the agent and users to trust a non-authoritative source for technical documentation, which could be used to serve biased or malicious content under the guise of official guides.
Audit Metadata