software-ios-ai-engine
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill handles untrusted user input via the
AskChatStoreandTier0Router. It implements a robust defense-in-depth strategy where a deterministic intent router classifies the input and applies safety boundaries—such as crisis redirects—before any generative model is invoked. Furthermore, the mandatoryAnchorValidatorensures that the AI engine only references facts provided in the secured evidence bundle. - [EXTERNAL_DOWNLOADS]: References in
data/sources.jsonand the documentation point to official Apple Developer resources and well-known open-source projects likesqlite-vec. These are used for architectural guidance and local search capabilities rather than unverified remote code execution, following the trusted vendor and well-known service guidelines. - [COMMAND_EXECUTION]: The
scripts/scaffold-composers.shutility is a local developer tool designed to generate Swift boilerplate code. Its operations are restricted to standard file creation commands likemkdirandprintf, posing no risk of privilege escalation or malicious command injection.
Audit Metadata