xcodebuildmcp-docs-command-review
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes content from files such as
CHANGELOG.mdand source code. These files could potentially contain malicious instructions intended to mislead the agent. Evidence includes: * Ingestion points: ReadsCHANGELOG.md,manifests/tools/*.yaml,manifests/workflows/*.yaml, andsrc/cli/**viaRead,Grep, andGlobtools. * Boundary markers: No explicit markers or instructions are provided to the agent to distinguish between data and instructions within the ingested content. * Capability inventory: Restricted toRead,Grep, andGlob. No network or execution capabilities detected. * Sanitization: No input sanitization or validation logic is present. - [NO_CODE]: The skill provides logic through markdown instructions only and does not execute scripts, binaries, or install external dependencies.
Audit Metadata