design
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is configured to read implementation guidelines from local files in the user's Downloads directory if they exist.
- Ingestion points: Specifically looks for
~/Downloads/docs/SwiftUI-Implementing-Liquid-Glass-Design.mdand~/Downloads/docs/AppKit-Implementing-Liquid-Glass-Design.md. - Boundary markers: The instructions do not specify boundary markers or instructions to ignore embedded commands within these files.
- Capability inventory: The skill possesses
WriteandEditcapabilities, meaning it could potentially modify project source code based on instructions ingested from these external documentation files. - Sanitization: No sanitization or content validation is mentioned before the agent processes the information from these local documents.
- [COMMAND_EXECUTION]: The
ui-prototypingsub-skill employs thexcodebuildcommand to verify that generated Swift prototypes are valid. - Evidence: The skill uses
xcodebuild buildto ensure UI variations are functional before they are presented to the user. - Context: This usage is restricted to the development environment and is consistent with the skill's primary purpose of UI prototyping.
- [EXTERNAL_DOWNLOADS]: The skill provides numerous references to external resources hosted on official and well-known Apple domains.
- Details: Links to
developer.apple.comfor Human Interface Guidelines, technical documentation, WWDC session videos, and font downloads are included throughout the instructional text. These are categorized as trusted services.
Audit Metadata