xcodebuildmcp-docs-command-review

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes content from files such as CHANGELOG.md and source code. These files could potentially contain malicious instructions intended to mislead the agent. Evidence includes: * Ingestion points: Reads CHANGELOG.md, manifests/tools/*.yaml, manifests/workflows/*.yaml, and src/cli/** via Read, Grep, and Glob tools. * Boundary markers: No explicit markers or instructions are provided to the agent to distinguish between data and instructions within the ingested content. * Capability inventory: Restricted to Read, Grep, and Glob. No network or execution capabilities detected. * Sanitization: No input sanitization or validation logic is present.
  • [NO_CODE]: The skill provides logic through markdown instructions only and does not execute scripts, binaries, or install external dependencies.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:08 PM
Security Audit — agent-trust-hub — xcodebuildmcp-docs-command-review