swiftui-pro
Pass
Audited by Gen Agent Trust Hub on Jun 18, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill contains legitimate and helpful instructions for Swift and SwiftUI development. It encourages best practices such as avoiding hardcoded secrets, using modern concurrency models, and prioritizing accessibility.
- [PROMPT_INJECTION]: Indirect Prompt Injection Surface. As a code review tool, the skill is designed to ingest and process user-provided Swift source code. This creates a surface where instructions embedded in code comments or strings within the analyzed project could potentially influence the agent's output.
- Ingestion points: User-provided Swift and SwiftUI source files (referenced in
SKILL.md). - Boundary markers: The instructions lack explicit directives to ignore or escape instructions that might be contained within the code being reviewed.
- Capability inventory: The skill is limited to generating textual review findings and does not have access to dangerous capabilities like arbitrary command execution or network writes.
- Sanitization: No specific sanitization measures for the analyzed code are described.
- [EXTERNAL_DOWNLOADS]: The skill references external resources and related agent skills hosted on GitHub (
github.com/twostraws/*). These references target a well-known community source for Swift tutorials and tools, and do not involve the execution of untrusted scripts or the installation of unknown packages. - [SAFE]: There is a minor discrepancy between the system-provided author ('moritztucher') and the metadata author ('Paul Hudson') in
SKILL.md. This appears to be a legitimate attribution to the source of the coding guidelines rather than a deceptive impersonation attempt.
Audit Metadata