appkit-accessibility-auditor
Pass
Audited by Gen Agent Trust Hub on Mar 25, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill is designed to process and analyze user-provided source code, creating an attack surface for indirect prompt injection where malicious instructions could be embedded in the code being audited.
- Ingestion points: Source code for NSViewController, NSView, and other AppKit components provided by the user (as described in SKILL.md).
- Boundary markers: Absent; there are no specific delimiters or instructions provided to the agent to distinguish between code to be audited and potentially malicious instructions within the input.
- Capability inventory: The agent generates code patches and remediation advice based on the input.
- Sanitization: No input validation or sanitization logic is defined for the content processed by the skill.
- [NO_CODE]: This skill consists entirely of instructional markdown and contains no executable scripts or binaries.
Audit Metadata