app-clips

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides accurate technical documentation for configuring iOS App Clip targets, including specific bundle ID prefix requirements and necessary raw entitlement keys for successful signing and installation.
  • [SAFE]: Guidance for data handoff via App Groups includes explicit security warnings that advise developers not to store passwords, refresh tokens, or other credentials in shared containers, which are not considered trust boundaries.
  • [SAFE]: External references to documentation use clear and unobfuscated URLs for technical guidance. There is no evidence of homoglyph attacks or malicious redirection in the provided links.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes developer queries to provide App Clip implementation advice, creating a standard instructional surface.
  • Ingestion points: User queries for App Clip architecture and setup guidance defined in SKILL.md.
  • Boundary markers: The skill incorporates structured Review Checklists and Validation Checkpoints in the reference files to ensure the user follows established development gates.
  • Capability inventory: The skill provides static documentation and does not utilize tools for command execution, file system modification, or network requests.
  • Sanitization: No runtime data sanitization is implemented as the skill serves static technical content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 11:13 AM
Security Audit — agent-trust-hub — app-clips