swiftui-pro

Pass

Audited by Gen Agent Trust Hub on Jun 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill contains legitimate and helpful instructions for Swift and SwiftUI development. It encourages best practices such as avoiding hardcoded secrets, using modern concurrency models, and prioritizing accessibility.
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface. As a code review tool, the skill is designed to ingest and process user-provided Swift source code. This creates a surface where instructions embedded in code comments or strings within the analyzed project could potentially influence the agent's output.
  • Ingestion points: User-provided Swift and SwiftUI source files (referenced in SKILL.md).
  • Boundary markers: The instructions lack explicit directives to ignore or escape instructions that might be contained within the code being reviewed.
  • Capability inventory: The skill is limited to generating textual review findings and does not have access to dangerous capabilities like arbitrary command execution or network writes.
  • Sanitization: No specific sanitization measures for the analyzed code are described.
  • [EXTERNAL_DOWNLOADS]: The skill references external resources and related agent skills hosted on GitHub (github.com/twostraws/*). These references target a well-known community source for Swift tutorials and tools, and do not involve the execution of untrusted scripts or the installation of unknown packages.
  • [SAFE]: There is a minor discrepancy between the system-provided author ('moritztucher') and the metadata author ('Paul Hudson') in SKILL.md. This appears to be a legitimate attribution to the source of the coding guidelines rather than a deceptive impersonation attempt.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 18, 2026, 01:51 AM
Security Audit — agent-trust-hub — swiftui-pro