appkit-accessibility-auditor

Pass

Audited by Gen Agent Trust Hub on Mar 25, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill is designed to process and analyze user-provided source code, creating an attack surface for indirect prompt injection where malicious instructions could be embedded in the code being audited.
  • Ingestion points: Source code for NSViewController, NSView, and other AppKit components provided by the user (as described in SKILL.md).
  • Boundary markers: Absent; there are no specific delimiters or instructions provided to the agent to distinguish between code to be audited and potentially malicious instructions within the input.
  • Capability inventory: The agent generates code patches and remediation advice based on the input.
  • Sanitization: No input validation or sanitization logic is defined for the content processed by the skill.
  • [NO_CODE]: This skill consists entirely of instructional markdown and contains no executable scripts or binaries.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 25, 2026, 02:36 PM