ios-developer

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted external data in the form of project requirements, constraints, and inputs as specified in the 'Instructions' and 'Response Approach' sections. It currently lacks explicit boundary markers (e.g., XML tags or delimiters) or sanitization instructions to prevent the agent from potentially following instructions embedded within these external inputs. While the skill maintains a specific persona as an iOS expert, the lack of input delimitation creates a potential surface where malicious project requirements could influence the agent's behavior or code generation output.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 03:04 PM
Security Audit — agent-trust-hub — ios-developer