qa-testing-ios
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/xcresult_to_junit.pyusessubprocess.runto execute the system utilityxcresulttool. This is used to extract test results from.xcresultbundles. The command is constructed using a list of arguments rather than a shell string, which is a standard security practice to prevent command injection vulnerabilities. - [INDIRECT_PROMPT_INJECTION]: The skill processes external tool output and test artifacts, creating a potential surface for indirect injection if an attacker were to influence test output content.
- Ingestion points: The
scripts/xcresult_to_junit.pyscript ingests data from.xcresultbundles and parses JSON output fromxcresulttool. - Boundary markers: No explicit prompt boundary markers are used as the script is a standalone processing utility.
- Capability inventory: The skill utilizes
subprocess.runfor command execution and performs file write operations to generate JUnit XML reports inscripts/xcresult_to_junit.py. - Sanitization: The script uses robust JSON parsing and list-based subprocess calls to ensure data from external bundles is handled safely without triggering shell-level execution.
Audit Metadata