foundation-models-on-device
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill describes patterns for processing untrusted user input via the
LanguageModelSession.respondandstreamResponsefunctions, which represents a vulnerability surface for indirect prompt injection. - Ingestion points: Natural language input is ingested through the
to:parameter inLanguageModelSessionmethods as shown inSKILL.mdsnippets. - Boundary markers: The documentation suggests using system instructions to implement safety measures (e.g., "Respond with 'I can't help with that' for dangerous requests"), but does not demonstrate the use of strict delimiters or explicit "ignore embedded instructions" headers for user-controlled strings.
- Capability inventory: The skill introduces a "Tool Calling" capability allowing the model to invoke Swift code via the
Toolprotocol (e.g.,RecipeSearchToolwhich performs recipe lookups). - Sanitization: The provided patterns do not include explicit sanitization or validation logic for data before it is interpolated into the model's context or passed to tool arguments.
Audit Metadata