review-ios
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill invokes commands such as
swiftlint,swift build, andswift teston files within the target repository. This is an inherent risk when performing automated reviews on untrusted code, as malicious repositories could contain code or configurations designed to execute during these phases. - [INDIRECT_PROMPT_INJECTION]: The skill analyzes untrusted Swift source code and project metadata, creating a surface for indirect prompt injection where malicious code could attempt to manipulate the agent's findings or bypass review gates.
- Ingestion points: Swift source files and project structure.
- Boundary markers: Gate-based workflow is present, but lacks explicit data delimiters for code content.
- Capability inventory: Access to shell commands including
git,grep, andswift. - Sanitization: None identified for file contents or filenames.
- [DYNAMIC_EXECUTION]: The verification step involves
swift buildandswift test, which compiles and runs code from the project targets at runtime.
Audit Metadata