swiftui-pro

Warn

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: MEDIUMMETADATA_POISONINGPROMPT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [METADATA_POISONING]: The skill specifies 'Paul Hudson' as the author in its YAML metadata, but the system identifies the author as 'getpoweredbyai'. This discrepancy is misleading and may be intended to gain user trust by impersonating a well-known community figure.
  • [PROMPT_INJECTION]: The skill contains instructions to assume 'iOS 26 exists' and target 'Swift 6.2'. These are intentional hallucinations designed to override the model's current knowledge. While likely for persona simulation, such overrides are categorized as prompt injection techniques.
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to review user-supplied SwiftUI code, which is a major ingestion point for untrusted data. The skill lacks instructions for the agent to treat this code as data rather than instructions.
  • Ingestion points: User-provided Swift and SwiftUI code files.
  • Boundary markers: Absent. No specific delimiters or safety warnings are provided for the agent to distinguish user code from its own instructions.
  • Capability inventory: The skill is restricted to code analysis and does not utilize tools for network access, file writing, or command execution.
  • Sanitization: No sanitization of user-provided content is performed.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 21, 2026, 01:59 PM
Security Audit — agent-trust-hub — swiftui-pro