xcode-test
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to install a dependency from the npm registry, a well-known package service.
- Evidence: The instructions in
SKILL.mdprompt the user to runnpx xcodebuildmcp@latestto add the required MCP server. - [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes untrusted data from the application under test, which could potentially contain malicious instructions.
- Ingestion points: The agent is instructed to capture and review simulator console logs via
mcp__xcodebuildmcp__get_sim_logsand analyze screenshot content inSKILL.md. - Boundary markers: The instructions do not specify the use of delimiters or clear "ignore instructions" wrappers for the external log data.
- Capability inventory: The skill utilizes a suite of tools for building, installing, and launching applications, as well as capturing logs and screenshots.
- Sanitization: There is no evidence of filtering or sanitizing the log content before it is processed by the agent.
Audit Metadata