apphouse-new-app
Pass
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by processing local project files during the setup workflow.\n- Ingestion points: As described in SKILL.md, the agent reads bundle IDs from Xcode project files, configuration data from GoogleService-Info.plist, and existing values from the apphouse.project.yml manifest.\n- Boundary markers: The instructions do not provide explicit boundary markers or directives to the agent to ignore instructions that might be embedded within these ingested files.\n- Capability inventory: The skill utilizes the Firebase CLI, App Store Connect API, and performs file system write operations to initialize the project manifest.\n- Sanitization: There is no documentation of sanitization or content validation for the data retrieved from external project files before it is processed by the agent.
Audit Metadata