app-store-review

Pass

Audited by Gen Agent Trust Hub on Aug 23, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to fetch documentation and release requirements from sosumi.ai (e.g., https://sosumi.ai/documentation/bundleresources/describing-use-of-required-reason-api). This is a non-authoritative third-party domain that is not recognized as a trusted organization or well-known service for official Apple development requirements. \n- [PROMPT_INJECTION]: The skill is designed to ingest and audit untrusted data from user-provided files such as privacy manifests, app code, and entitlements without proper boundary markers, creating a surface for indirect prompt injection. \n
  • Ingestion points: The skill analyzes user-supplied PrivacyInfo.xcprivacy, app code, and entitlement plists as described in SKILL.md and references/review-checklists.md. \n
  • Boundary markers: Absent. The skill provides no instructions to wrap external content in delimiters or to ignore instructions embedded within the analyzed data. \n
  • Capability inventory: The agent environment typically supports shell commands, filesystem access, and web browsing, which could be targeted if the agent follows malicious instructions found in audited files. \n
  • Sanitization: Absent. There are no instructions to sanitize, escape, or validate the content of external files before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 23, 2026, 09:03 AM
Security Audit — agent-trust-hub — app-store-review