tailrocks-swift-project-audit
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill audits external Swift project files, which serves as a potential vector for indirect prompt injection. Maliciously crafted content within the scanned project files (such as comments or metadata) could attempt to influence the agent's behavior or bias its findings.
- [COMMAND_EXECUTION]: The skill leverages standard macOS development tools including xcodebuild, swift-format, periphery, and swiftlint. These commands are necessary for the skill's auditing function and are used within their intended scope.
- [EXTERNAL_DOWNLOADS]: The skill references official Apple metadata services (gdmf.apple.com) and a vendor-specific directory structure ('tailrocks-swift-project-setup'). Both the domain and the vendor 'tailrocks' are recognized as trusted resources in this context, and these references do not escalate the verdict.
Audit Metadata