macos-signing-entitlements
Pass
Audited by Gen Agent Trust Hub on Jun 25, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill defines a workflow using official macOS development tools like codesign, spctl, and security to inspect binary integrity and entitlements. The instructions are consistent with legitimate software development practices.- [PROMPT_INJECTION]: The skill processes external files (binaries, app bundles, and plists) which could potentially contain malicious content aimed at indirect prompt injection. However, the risk is minimal as the skill is limited to diagnostic inspection commands.
- Ingestion points: File paths for apps and binaries in SKILL.md.
- Boundary markers: None present.
- Capability inventory: Execution of local diagnostic commands (codesign, spctl, plutil) in SKILL.md.
- Sanitization: None specified.
Audit Metadata