skills/vabole/apple-skills/hig/Gen Agent Trust Hub

hig

Pass

Audited by Gen Agent Trust Hub on May 10, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [SAFE]: The skill predominantly consists of local Markdown files that provide design guidelines for various Apple platforms. These files are static and contain legitimate educational content extracted from Apple's developer documentation.
  • [EXTERNAL_DOWNLOADS]: The instructions in SKILL.md suggest that the agent can fetch additional documentation from an unofficial third-party mirror at sosumi.ai if content is not available locally. While this is an unofficial source, it is used exclusively for retrieving textual documentation.
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface because it is configured to ingest documentation from external, unofficial web sources.
  • Ingestion points: External URLs from the sosumi.ai mirror suggested in SKILL.md.
  • Boundary markers: Absent; there are no explicit instructions for the agent to disregard potential directions embedded within the external documentation.
  • Capability inventory: The skill performs text searching using grep and reads files. It does not request permissions for arbitrary command execution or system-level changes.
  • Sanitization: Absent; content fetched from external sources is processed without filtering or validation.
Audit Metadata
Risk Level
SAFE
Analyzed
May 10, 2026, 01:51 PM