swift-ios
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The
scripts/verify.shutility script creates a potential indirect prompt injection surface by reading content from local.swiftfiles and returning it directly to the agent's context. - Ingestion points: The
scripts/verify.shscript (referenced in the main SKILL.md body) iterates through all.swiftfiles in the target directories to detect prohibited patterns. - Boundary markers: The script does not utilize delimiters or specific instructions to the agent to treat the extracted file content as untrusted data.
- Capability inventory: The skill provides the agent with instructions to perform file system operations, networking, and shell command execution using the
xcodebuildtoolchain. - Sanitization: No sanitization or filtering is applied to the matches found in the codebase before they are presented to the agent, allowing potential injection strings in comments or code to enter the prompt.
Audit Metadata