swift-testing
Pass
Audited by Gen Agent Trust Hub on Jul 5, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTIONNO_CODE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill's
SKILL.mdinstructions recommend fetching additional documentation fromhttps://sosumi.aiif the required information is not found in the local files. This domain is a known Markdown proxy for Apple's official DocC documentation, intended to provide clean text for AI agents.\n- [PROMPT_INJECTION]: The instruction to ingest external documentation fromsosumi.aicreates a surface for indirect prompt injection. While the source is a documentation mirror, the agent is directed to process external content without explicit boundary markers or sanitization rules. This risk is classified as minimal because the skill lacks executable capabilities (no scripts, file-system writing, or network exfiltration tools), which prevents an injection from escalating into a more serious attack.\n- [NO_CODE]: The skill is a 'no code' extension, containing only static Markdown files. There are no Python or Node.js scripts, configuration files (likepackage.jsonorrequirements.txt), or shell commands that could be executed in the agent's environment.
Audit Metadata