swift-testing

Pass

Audited by Gen Agent Trust Hub on Jul 5, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTIONNO_CODE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill's SKILL.md instructions recommend fetching additional documentation from https://sosumi.ai if the required information is not found in the local files. This domain is a known Markdown proxy for Apple's official DocC documentation, intended to provide clean text for AI agents.\n- [PROMPT_INJECTION]: The instruction to ingest external documentation from sosumi.ai creates a surface for indirect prompt injection. While the source is a documentation mirror, the agent is directed to process external content without explicit boundary markers or sanitization rules. This risk is classified as minimal because the skill lacks executable capabilities (no scripts, file-system writing, or network exfiltration tools), which prevents an injection from escalating into a more serious attack.\n- [NO_CODE]: The skill is a 'no code' extension, containing only static Markdown files. There are no Python or Node.js scripts, configuration files (like package.json or requirements.txt), or shell commands that could be executed in the agent's environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 5, 2026, 03:29 PM
Security Audit — agent-trust-hub — swift-testing