iphone-duo-readiness

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill involves analyzing user-supplied source code, which creates a potential surface for indirect prompt injection if the code contains malicious instructions.\n
  • Ingestion points: The agent ingests external source code files (Swift, Objective-C) from the user's project.\n
  • Boundary markers: There are no explicit instructions or delimiters to isolate code comments or string literals from the agent's logical processing.\n
  • Capability inventory: The skill itself does not invoke any tools with high-risk capabilities such as network access, file system writes, or shell command execution.\n
  • Sanitization: The instructions do not specify any sanitization or validation steps for the code content before it is processed by the agent.\n- [SAFE]: The content is purely informational and follows standard developer documentation patterns. It does not utilize any dynamic context injection, remote code execution, or persistence mechanisms.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 10:59 AM
Security Audit — agent-trust-hub — iphone-duo-readiness