review-ios

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill invokes commands such as swiftlint, swift build, and swift test on files within the target repository. This is an inherent risk when performing automated reviews on untrusted code, as malicious repositories could contain code or configurations designed to execute during these phases.
  • [INDIRECT_PROMPT_INJECTION]: The skill analyzes untrusted Swift source code and project metadata, creating a surface for indirect prompt injection where malicious code could attempt to manipulate the agent's findings or bypass review gates.
  • Ingestion points: Swift source files and project structure.
  • Boundary markers: Gate-based workflow is present, but lacks explicit data delimiters for code content.
  • Capability inventory: Access to shell commands including git, grep, and swift.
  • Sanitization: None identified for file contents or filenames.
  • [DYNAMIC_EXECUTION]: The verification step involves swift build and swift test, which compiles and runs code from the project targets at runtime.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 09:17 AM
Security Audit — agent-trust-hub — review-ios