xcode-test

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install a dependency from the npm registry, a well-known package service.
  • Evidence: The instructions in SKILL.md prompt the user to run npx xcodebuildmcp@latest to add the required MCP server.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes untrusted data from the application under test, which could potentially contain malicious instructions.
  • Ingestion points: The agent is instructed to capture and review simulator console logs via mcp__xcodebuildmcp__get_sim_logs and analyze screenshot content in SKILL.md.
  • Boundary markers: The instructions do not specify the use of delimiters or clear "ignore instructions" wrappers for the external log data.
  • Capability inventory: The skill utilizes a suite of tools for building, installing, and launching applications, as well as capturing logs and screenshots.
  • Sanitization: There is no evidence of filtering or sanitizing the log content before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 04:15 AM
Security Audit — agent-trust-hub — xcode-test