core-ml

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides templates (ModelUpdater in patterns.md and MLModelManager in templates.md) for downloading Core ML models from remote URLs using URLSession.shared.download. This is a standard pattern for dynamic model updates in mobile applications.- [DYNAMIC_EXECUTION]: The code utilizes MLModel.compileModel(at:) to compile downloaded .mlmodel files into an executable format (.mlmodelc) for the device's hardware (Neural Engine/GPU). This is a native Apple API for runtime model preparation.- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data (images, video frames, and text) through classification and analysis tools. While this creates a potential attack surface if the agent acts on unvalidated output, the skill uses standard Vision and Natural Language APIs which have built-in stability and the agent is guided by developer-defined confidence thresholds.
  • Ingestion points: classify(_:maxResults:minimumConfidence:) in ImageClassifier.swift, detectSentiment(_:), recognizeEntities(_:) in TextAnalyzer.swift, and camera frame processing in CameraMLPipeline.
  • Boundary markers: The templates recommend using confidence thresholds (e.g., minimumConfidence: 0.7) to filter results.
  • Capability inventory: File system writes (caching models), network downloads (fetching models), and ML inference operations.
  • Sanitization: The skill provides logic for filtering low-confidence results but does not perform content-level sanitization of the extracted text/labels.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 07:15 AM