hig
Pass
Audited by Gen Agent Trust Hub on May 10, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
- [SAFE]: The skill predominantly consists of local Markdown files that provide design guidelines for various Apple platforms. These files are static and contain legitimate educational content extracted from Apple's developer documentation.
- [EXTERNAL_DOWNLOADS]: The instructions in
SKILL.mdsuggest that the agent can fetch additional documentation from an unofficial third-party mirror atsosumi.aiif content is not available locally. While this is an unofficial source, it is used exclusively for retrieving textual documentation. - [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface because it is configured to ingest documentation from external, unofficial web sources.
- Ingestion points: External URLs from the
sosumi.aimirror suggested inSKILL.md. - Boundary markers: Absent; there are no explicit instructions for the agent to disregard potential directions embedded within the external documentation.
- Capability inventory: The skill performs text searching using
grepand reads files. It does not request permissions for arbitrary command execution or system-level changes. - Sanitization: Absent; content fetched from external sources is processed without filtering or validation.
Audit Metadata