hig-platforms
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to check for and read a project-specific context file (.claude/apple-design-context.md), which could be leveraged to provide malicious instructions via project files.
- Ingestion points: .claude/apple-design-context.md (referenced in SKILL.md).
- Boundary markers: Absent; the instructions do not provide delimiters or warnings for the content of the context file.
- Capability inventory: No tools are explicitly requested in the frontmatter, but the agent typically has file-reading and shell capabilities.
- Sanitization: Absent; the skill does not suggest any validation or filtering of the context file content.
Audit Metadata