mobile-monorepo-ios

Pass

Audited by Gen Agent Trust Hub on Aug 22, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses standard utilities such as git, xcodebuild, and xcrun to verify the local development environment and project status. These operations are scoped to the repository and intended for discovery.
  • [DATA_EXFILTRATION]: The instructions include a strict Secret Boundary gate that prohibits the exposure of credentials in source code, logs, or screenshots, ensuring sensitive data remains protected.
  • [REMOTE_CODE_EXECUTION]: The framework enforces the use of pinned toolchain versions and repository scripts, explicitly warning against the auto-installation of unverified third-party companions or tools.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a clear ingestion and verification process for project data. 1. Ingestion points: Reads package.json, app.json, and repository scripts. 2. Boundary markers: Utilizes a Proof Contract and Stop Gates to delineate task authority. 3. Capability inventory: Includes local shell execution and authorized filesystem writes. 4. Sanitization: Applies a Secret Boundary to prevent sensitive data exposure during analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 22, 2026, 08:31 AM
Security Audit — agent-trust-hub — mobile-monorepo-ios