ios-widget-design

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill facilitates the review of untrusted user-provided content, such as screenshots and SwiftUI code. This ingestion of external data presents a surface for indirect prompt injection, where instructions could be embedded within design assets to influence agent behavior.
  • Ingestion points: Identified in SKILL.md as "screenshots, specifications, or SwiftUI views."
  • Boundary markers: The skill lacks explicit delimiters or instructions to ignore commands within the analyzed data.
  • Capability inventory: The skill is strictly documentation-based and does not include tools or scripts.
  • Sanitization: No methods for sanitizing or escaping external content are provided.
  • [NO_CODE]: The skill consists exclusively of markdown documentation and YAML configuration. It contains no executable scripts or binary files.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 07:38 AM
Security Audit — agent-trust-hub — ios-widget-design