swift-private-bundle

Pass

Audited by Gen Agent Trust Hub on Mar 28, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses shell commands including git, gh, rg, and swift to perform repository updates, code searches, and dependency resolution.
  • [EXTERNAL_DOWNLOADS]: It downloads repository metadata and source code from GitHub, specifically from the hocgin organization. These operations target a well-known service and are consistent with the skill's primary functionality.
  • [PROMPT_INJECTION]: The skill processes external data from local mirrors and remote files (e.g., README, Package.swift), which presents an indirect prompt injection surface. The ingestion points include ~/GitHub/knowledge/ and gh search code output. No explicit boundary markers or sanitization logic is provided, but the capabilities are limited to standard developer workflows.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 28, 2026, 12:37 PM
Security Audit — agent-trust-hub — swift-private-bundle