ultrapolish-ios

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is a resource for iOS developers to improve app UX and UI cohesion. It includes Swift assets for haptics, motion, and color management, alongside extensive documentation. No malicious code, credential theft, or unauthorized data exfiltration patterns were found.
  • [COMMAND_EXECUTION]: The skill suggests the use of diagnostic grep commands to perform a project "intake" phase, allowing the agent to identify existing design tokens and patterns (e.g., searching for cornerRadius or Font declarations in the Sources/ directory). These commands are read-only and limited to the local project scope.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted project documentation and source code to inform its design recommendations. While this presents an ingestion surface for potentially malicious data, the skill does not utilize high-privilege tools or network resources, mitigating the threat of exploitation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 02:51 PM
Security Audit — agent-trust-hub — ultrapolish-ios