skills/vabole/apple-skills/uikit/Gen Agent Trust Hub

uikit

Warn

Audited by Gen Agent Trust Hub on May 12, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The SKILL.md file explicitly instructs the agent to fetch additional documentation from https://sosumi.ai if the requested topic is not found in the local skill files or other installed Apple skills. This domain is an unofficial, third-party mirror of Apple's documentation, posing a risk of content manipulation or tracking by an untrusted external entity.
  • [PROMPT_INJECTION]: The skill uses authoritative instructional language (e.g., "If no installed skill has the page, use... the sosumi.ai Markdown mirror") which, while typical for documentation skills, directs agent behavior toward external resources.
  • [SAFE]: The provided markdown documentation files (nslayoutconstraint.md, uiapplication.md, etc.) appear to be legitimate, static extracts of UIKit framework documentation. No obfuscation, hardcoded credentials, or persistence mechanisms were detected in the analyzed files.
Audit Metadata
Risk Level
MEDIUM
Analyzed
May 12, 2026, 02:44 AM