xcode-project-setup

Pass

Audited by Gen Agent Trust Hub on May 19, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the download of third-party libraries through the official Swift Package Manager (SPM). It references well-known and trusted sources, such as the official Firebase iOS SDK repository on GitHub, to ensure the latest versions are used.
  • [COMMAND_EXECUTION]: Executes a local Swift package via swift run to perform programmatic modifications to Xcode project files. It also adds standard shell script build phases to the project for features like Firebase Crashlytics, which is a routine development task.
  • [PROMPT_INJECTION]: Includes instructional constraints that direct the AI agent to use specific tools (Swift) and avoid others (Ruby). These are designed to ensure the skill operates as intended within a modern macOS development environment rather than bypassing safety protocols.
Audit Metadata
Risk Level
SAFE
Analyzed
May 19, 2026, 01:15 PM
Security Audit — agent-trust-hub — xcode-project-setup