xcodebuildmcp-test-boundary-review

Pass

Audited by Gen Agent Trust Hub on May 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches documentation and contribution guidelines from the project-specific domain xcodebuildmcp.com to provide context for test reviews.\n- [COMMAND_EXECUTION]: Instructs the agent to execute standard local validation routines including npm test, npm run typecheck, and npx skill-check. These are typical for development workflows and are used here to verify the integrity of the test suite.\n- [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface as it reads external documentation content that is subsequently processed by the agent. \n
  • Ingestion points: External Markdown files located at xcodebuildmcp.com/app/docs/_content/testing.mdx and contributing.mdx. \n
  • Boundary markers: None specified. \n
  • Capability inventory: Local file system read access and command execution via npm and npx. \n
  • Sanitization: No explicit content sanitization or instruction-filtering is defined for the retrieved remote documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
May 16, 2026, 03:42 AM