hig-components-system

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists entirely of Markdown documentation and instructional text. No scripts, executables, or configuration files that trigger side effects are included in the skill package.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a surface for indirect prompt injection as it is designed to ingest and interpret user-provided design scenarios to provide HIG-compliant advice.
  • Ingestion points: User queries described in SKILL.md metadata (e.g., "how do I design a widget," "what should my notification look like").
  • Boundary markers: None identified.
  • Capability inventory: No capabilities for subprocess execution, file writing, or network operations exist across any of the analyzed files.
  • Sanitization: None identified.
  • Assessment: Due to the complete absence of executable capabilities, the potential for harm through indirect prompt injection is negligible.
  • [EXTERNAL_DOWNLOADS]: The reference files (references/*.md) link to canonical Apple developer documentation and the author's own domain (raintree.technology). These represent standard documentation practices targeting trusted and vendor-owned resources.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 10:06 PM
Security Audit — agent-trust-hub — hig-components-system