core-animation

Pass

Audited by Gen Agent Trust Hub on Jul 5, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a technical API reference for the QuartzCore (Core Animation) framework, containing comprehensive local documentation for classes like CALayer, CAAnimation, CATransaction, and their various subclasses.
  • [EXTERNAL_DOWNLOADS]: SKILL.md describes procedures for fetching additional documentation from sosumi.ai (a common markdown mirror for Apple documentation) or via the pnpm fetch-doc utility if a specific symbol is not present in the local file set. These references are restricted to documentation retrieval tasks.
  • [PROMPT_INJECTION]: The instructions focus entirely on providing structured documentation responses and do not contain any patterns intended to override agent behavior, bypass safety protocols, or leak system prompts.
  • [DATA_EXFILTRATION]: No evidence of hardcoded credentials, access to sensitive local file paths (such as SSH keys or environment variables), or unauthorized data transmission was found.
  • [REMOTE_CODE_EXECUTION]: The skill does not implement any remote code execution vectors, shell command piping from external sources, or dynamic code evaluation mechanisms.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 5, 2026, 03:29 PM
Security Audit — agent-trust-hub — core-animation