swift-architecture
Pass
Audited by Gen Agent Trust Hub on Aug 23, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill contains an indirect prompt injection surface by instructing the agent to ingest and analyze untrusted data from the local project environment.
- Ingestion points: The Decision Workflow in
SKILL.mddirects the agent to "Inspect the existing project conventions, deployment target, Swift mode, dependencies, and tests" (Step 1). - Boundary markers: No specific delimiters or instructions to ignore potential malicious prompts embedded within analyzed project files are provided.
- Capability inventory: The skill facilitates architectural decision-making and implementation, which involves file system read and write operations within the agent's workspace.
- Sanitization: The instructions do not define any sanitization or validation processes for the ingested project content.
- [EXTERNAL_DOWNLOADS]: The skill provides links to documentation hosted on an unofficial domain rather than the official developer site.
- Evidence:
SKILL.mdcontains references to documentation onsosumi.ai(e.g.,https://sosumi.ai/documentation/observation). While these are informational links, the domain is an unofficial mirror of Apple's developer documentation.
Audit Metadata