spotlight-indexing
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: Potential for indirect prompt injection during the project context detection phase.
- Ingestion points: The skill uses
GlobandGrepto scan project files for existing Spotlight and navigation logic (e.g.,**/*Spotlight*.swift,NSUserActivity) inSKILL.md. - Boundary markers: Absent. The instructions do not implement delimiters or ignore-instructions for the content ingested from the scanned files.
- Capability inventory: The skill possesses extensive capabilities including
Write,Edit, andBashtools used to modify the project structure and source code. - Sanitization: Absent. The agent is instructed to identify what is missing or how to integrate based on existing code without validating the content of those files for malicious directives.
Audit Metadata