skills/leonardoacosta/skills/swift/Gen Agent Trust Hub

swift

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute several system commands and build tools, including xcodegen, xcodebuild, plutil, and devicectl. These are standard tools for iOS and macOS development.
  • [COMMAND_EXECUTION]: It describes a bridge mechanism using launchctl to interact with the macOS GUI session (launchctl kickstart, launchctl print). This is a legitimate workaround for keychain access limitations in background sessions.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection through repository-controlled files that it processes during build operations.
  • Ingestion points: Project configuration files (project.yml), build settings (.xcconfig), and source code files within the repository.
  • Boundary markers: None identified; the skill assumes repository files are trusted sources of truth for the project layout.
  • Capability inventory: The skill has access to shell execution (Bash) and the ability to trigger build processes and local process management.
  • Sanitization: There is no explicit sanitization of environment variables like $SCHEME, $DESTINATION, or $DEVICE_ID before they are interpolated into shell commands.
  • [DATA_EXFILTRATION]: The skill includes explicit security requirements to prevent data exposure, such as storing identifiers in ignored .xcconfig files and keeping credentials in approved secret stores rather than logs or portable guidance.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 09:40 PM
Security Audit — agent-trust-hub — swift