skills/k97/skills/apple-appicon/Gen Agent Trust Hub

apple-appicon

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to visually inspect user-provided images for design compliance. While this creates a surface for potential injection via image content (OCR or metadata), it is a core feature of the skill.
  • Ingestion points: User-supplied path evaluated in SKILL.md.
  • Boundary markers: The agent is explicitly instructed to limit reports to 'one or two sentences' and 'advisory only'.
  • Capability inventory: File system writes and local shell execution (sips, magick, swift) as defined in recipes.
  • Sanitization: Shell scripts in the scripts/ directory utilize variable quoting to prevent command injection from file names.\n- [SAFE]: The skill uses native system utilities and standard development tools to perform legitimate image processing tasks. No evidence of data exfiltration, obfuscation, or persistence was found.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 09:33 AM
Security Audit — agent-trust-hub — apple-appicon