foundation-models-on-device

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill describes patterns for processing untrusted user input via the LanguageModelSession.respond and streamResponse functions, which represents a vulnerability surface for indirect prompt injection.
  • Ingestion points: Natural language input is ingested through the to: parameter in LanguageModelSession methods as shown in SKILL.md snippets.
  • Boundary markers: The documentation suggests using system instructions to implement safety measures (e.g., "Respond with 'I can't help with that' for dangerous requests"), but does not demonstrate the use of strict delimiters or explicit "ignore embedded instructions" headers for user-controlled strings.
  • Capability inventory: The skill introduces a "Tool Calling" capability allowing the model to invoke Swift code via the Tool protocol (e.g., RecipeSearchTool which performs recipe lookups).
  • Sanitization: The provided patterns do not include explicit sanitization or validation logic for data before it is interpolated into the model's context or passed to tool arguments.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:39 PM
Security Audit — agent-trust-hub — foundation-models-on-device