hig-components-system
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists entirely of Markdown documentation and instructional text. No scripts, executables, or configuration files that trigger side effects are included in the skill package.
- [INDIRECT_PROMPT_INJECTION]: The skill defines a surface for indirect prompt injection as it is designed to ingest and interpret user-provided design scenarios to provide HIG-compliant advice.
- Ingestion points: User queries described in
SKILL.mdmetadata (e.g., "how do I design a widget," "what should my notification look like"). - Boundary markers: None identified.
- Capability inventory: No capabilities for subprocess execution, file writing, or network operations exist across any of the analyzed files.
- Sanitization: None identified.
- Assessment: Due to the complete absence of executable capabilities, the potential for harm through indirect prompt injection is negligible.
- [EXTERNAL_DOWNLOADS]: The reference files (
references/*.md) link to canonical Apple developer documentation and the author's own domain (raintree.technology). These represent standard documentation practices targeting trusted and vendor-owned resources.
Audit Metadata