core-ml
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides templates (
ModelUpdaterinpatterns.mdandMLModelManagerintemplates.md) for downloading Core ML models from remote URLs usingURLSession.shared.download. This is a standard pattern for dynamic model updates in mobile applications.- [DYNAMIC_EXECUTION]: The code utilizesMLModel.compileModel(at:)to compile downloaded.mlmodelfiles into an executable format (.mlmodelc) for the device's hardware (Neural Engine/GPU). This is a native Apple API for runtime model preparation.- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data (images, video frames, and text) through classification and analysis tools. While this creates a potential attack surface if the agent acts on unvalidated output, the skill uses standard Vision and Natural Language APIs which have built-in stability and the agent is guided by developer-defined confidence thresholds. - Ingestion points:
classify(_:maxResults:minimumConfidence:)inImageClassifier.swift,detectSentiment(_:),recognizeEntities(_:)inTextAnalyzer.swift, and camera frame processing inCameraMLPipeline. - Boundary markers: The templates recommend using confidence thresholds (e.g.,
minimumConfidence: 0.7) to filter results. - Capability inventory: File system writes (caching models), network downloads (fetching models), and ML inference operations.
- Sanitization: The skill provides logic for filtering low-confidence results but does not perform content-level sanitization of the extracted text/labels.
Audit Metadata