design

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is configured to read implementation guidelines from local files in the user's Downloads directory if they exist.
  • Ingestion points: Specifically looks for ~/Downloads/docs/SwiftUI-Implementing-Liquid-Glass-Design.md and ~/Downloads/docs/AppKit-Implementing-Liquid-Glass-Design.md.
  • Boundary markers: The instructions do not specify boundary markers or instructions to ignore embedded commands within these files.
  • Capability inventory: The skill possesses Write and Edit capabilities, meaning it could potentially modify project source code based on instructions ingested from these external documentation files.
  • Sanitization: No sanitization or content validation is mentioned before the agent processes the information from these local documents.
  • [COMMAND_EXECUTION]: The ui-prototyping sub-skill employs the xcodebuild command to verify that generated Swift prototypes are valid.
  • Evidence: The skill uses xcodebuild build to ensure UI variations are functional before they are presented to the user.
  • Context: This usage is restricted to the development environment and is consistent with the skill's primary purpose of UI prototyping.
  • [EXTERNAL_DOWNLOADS]: The skill provides numerous references to external resources hosted on official and well-known Apple domains.
  • Details: Links to developer.apple.com for Human Interface Guidelines, technical documentation, WWDC session videos, and font downloads are included throughout the instructional text. These are categorized as trusted services.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 01:28 AM