hig-components-controls

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists of static markdown files providing design guidance. It does not include any scripts, executable code, or configurations that grant the agent access to restricted tools.
  • [EXTERNAL_DOWNLOADS]: The skill contains numerous links to the official Apple Developer Documentation (developer.apple.com). These references to a well-known service are intended for informational purposes and do not trigger automatic downloads or execution.
  • [INDIRECT_PROMPT_INJECTION]: The skill instructions direct the agent to check for a local file .claude/apple-design-context.md for project-specific design context.
  • Ingestion points: .claude/apple-design-context.md (referenced in SKILL.md).
  • Boundary markers: None provided; the agent is instructed to use the existing context.
  • Capability inventory: No capabilities for network operations, file writing, or command execution are present across any of the skill's files.
  • Sanitization: None detected.
  • Reasoning: While this allows the ingestion of external data, the skill lacks the functional capabilities required to exploit this surface for malicious purposes.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 10:06 PM
Security Audit — agent-trust-hub — hig-components-controls