swift-private-bundle
Pass
Audited by Gen Agent Trust Hub on Mar 28, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill uses shell commands including
git,gh,rg, andswiftto perform repository updates, code searches, and dependency resolution. - [EXTERNAL_DOWNLOADS]: It downloads repository metadata and source code from GitHub, specifically from the
hocginorganization. These operations target a well-known service and are consistent with the skill's primary functionality. - [PROMPT_INJECTION]: The skill processes external data from local mirrors and remote files (e.g., README, Package.swift), which presents an indirect prompt injection surface. The ingestion points include
~/GitHub/knowledge/andgh search codeoutput. No explicit boundary markers or sanitization logic is provided, but the capabilities are limited to standard developer workflows.
Audit Metadata