software-ios-design

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill's common script scripts/_xcodebuildmcp_common.sh attempts to resolve the xcodebuildmcp tool by calling npx -y xcodebuildmcp@latest. This fetches the latest version of the tool from the npm registry at runtime if it is not installed locally. Additionally, data/sources.json and SKILL.md reference external developer utilities including xcbeautify (GitHub), DocSetQuery (GitHub), and sosumi.ai (a documentation search service).
  • [REMOTE_CODE_EXECUTION]: The resolution of xcodebuildmcp via npx constitutes remote code execution, as the package is downloaded and run immediately. However, xcodebuildmcp is an official tool from Sentry, a well-known technology company, and its use here is consistent with standard developer workflows for simulator automation.
  • [COMMAND_EXECUTION]: The skill provides several shell scripts (scripts/build-ios.sh, scripts/run-ios.sh, scripts/test-ios.sh, scripts/capture-screenshot.sh) that execute xcodebuildmcp commands to perform builds, launch applications, run tests, and capture simulator screenshots. These commands are integral to the skill's stated purpose of design verification.
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its core workflow of processing external project data.
  • Ingestion points: The agent is instructed to ingest SwiftUI source code, build logs, and simulator UI snapshots for auditing (documented in SKILL.md and references/ai-design-review.md).
  • Boundary markers: There are no specific delimiters or instructions provided to the agent to distinguish between its own system instructions and potentially malicious commands embedded in the code or logs it audits.
  • Capability inventory: The skill possesses the capability to execute shell commands, compile code, and perform network requests via the integrated developer tools.
  • Sanitization: No sanitization or filtering logic is present for the ingested project data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:07 PM
Security Audit — agent-trust-hub — software-ios-design