swift-architecture

Pass

Audited by Gen Agent Trust Hub on Aug 23, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill contains an indirect prompt injection surface by instructing the agent to ingest and analyze untrusted data from the local project environment.
  • Ingestion points: The Decision Workflow in SKILL.md directs the agent to "Inspect the existing project conventions, deployment target, Swift mode, dependencies, and tests" (Step 1).
  • Boundary markers: No specific delimiters or instructions to ignore potential malicious prompts embedded within analyzed project files are provided.
  • Capability inventory: The skill facilitates architectural decision-making and implementation, which involves file system read and write operations within the agent's workspace.
  • Sanitization: The instructions do not define any sanitization or validation processes for the ingested project content.
  • [EXTERNAL_DOWNLOADS]: The skill provides links to documentation hosted on an unofficial domain rather than the official developer site.
  • Evidence: SKILL.md contains references to documentation on sosumi.ai (e.g., https://sosumi.ai/documentation/observation). While these are informational links, the domain is an unofficial mirror of Apple's developer documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 23, 2026, 09:04 AM
Security Audit — agent-trust-hub — swift-architecture