swift-codable
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEDATA_EXFILTRATIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The file
SKILL.mdcontains Swift code examples that utilizeURLSessionto perform network operations, such as fetching data fromhttps://api.example.com/users/. - [EXTERNAL_DOWNLOADS]: The
Referencessection inSKILL.mdlinks to external documentation hosted onsosumi.ai, which is a third-party domain not included in the trusted vendors list. - [INDIRECT_PROMPT_INJECTION]: The skill provides patterns for ingesting and parsing external data, which presents a potential surface for indirect prompt injection if the parsed data is subsequently used in LLM prompts.
- Ingestion points: The
fetchUserfunction inSKILL.mddemonstrates fetching data from an external API URL. - Boundary markers: The implementation uses
JSONDecoderto enforce structure on the incoming data, which acts as a boundary against unstructured content. - Capability inventory: The skill documents the use of
URLSessionfor network access andJSONDecoderfor data processing. - Sanitization: Type-safe decoding into Swift structs provides validation of the incoming data schema.
Audit Metadata