apple-intelligence
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references the official
apple/foundation-models-utilitiespackage from GitHub (https://github.com/apple/foundation-models-utilities). This is a legitimate resource from a trusted organization intended to provide emerging patterns for the Foundation Models framework. - [INDIRECT_PROMPT_INJECTION]: The skill implements features that ingest untrusted user data, such as prompts and images, for processing by language and vision models, which presents an attack surface for indirect injection.
- Ingestion points: User-supplied content is ingested via the
respond(to:)method andAttachmentsegments in the Foundation Models framework. - Boundary markers: The skill emphasizes the "Instructions vs Prompts" hierarchy to prioritize developer-defined safety rules over potentially malicious user input, as described in
foundation-models/safety-and-guardrails.md. - Capability inventory: The skill supports tool calling (executing Swift code), network operations via Private Cloud Compute or third-party backends, and reading files from
~/Downloads/docs/for extra documentation context. - Sanitization: The skill utilizes the framework's built-in safety stack, including input/output guardrails and instruction-based constraints, to filter harmful generated content.
Audit Metadata