spotlight-indexing

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Potential for indirect prompt injection during the project context detection phase.
  • Ingestion points: The skill uses Glob and Grep to scan project files for existing Spotlight and navigation logic (e.g., **/*Spotlight*.swift, NSUserActivity) in SKILL.md.
  • Boundary markers: Absent. The instructions do not implement delimiters or ignore-instructions for the content ingested from the scanned files.
  • Capability inventory: The skill possesses extensive capabilities including Write, Edit, and Bash tools used to modify the project structure and source code.
  • Sanitization: Absent. The agent is instructed to identify what is missing or how to integrate based on existing code without validating the content of those files for malicious directives.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 01:19 PM
Security Audit — agent-trust-hub — spotlight-indexing