skills/midudev/autoskills/clerk-swift/Gen Agent Trust Hub

clerk-swift

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONMETADATA_POISONING
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructions direct the agent to extract a URL from the README.md of an installed package (clerk-ios), fetch the content of that URL via WebFetch, and use it as a source of truth to "compile a required-step checklist" for project implementation. This creates a vulnerability where a malicious package could point the agent to a documentation site containing prompt injection instructions designed to trick the agent into adding unauthorized capabilities or domains.
  • Ingestion points: Remote markdown content fetched at runtime based on URLs found in local package files.
  • Boundary markers: Absent. The agent is explicitly instructed to "Verify and complete all quickstart prerequisites" based on the external content.
  • Capability inventory: The agent has the ability to modify Xcode project files, add app capabilities, and manage associated domains.
  • Sanitization: No validation or filtering of the remote content is mentioned before it is processed as instructions.
  • [EXTERNAL_DOWNLOADS]: The skill makes several network requests, including fetching remote documentation using the WebFetch tool and calling Clerk's environment endpoint (/v1/environment). It also manages the installation of the clerk-ios package from external registries.
  • [COMMAND_EXECUTION]: The skill performs automated configuration of the iOS development environment, including installing packages via Swift Package Manager and modifying project entitlements, such as Associated Domains and app capabilities.
  • [METADATA_POISONING]: The skill's metadata lists "clerk" as the author, which conflicts with the provided author context of "midudev." This discrepancy could lead users to misattribute the skill's origin as an official integration from the service provider.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 11:19 PM
Security Audit — agent-trust-hub — clerk-swift