software-ios-runtime-debugging

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes standard command-line tools for iOS development and troubleshooting.
  • Suggests clearing project build caches by deleting the local DerivedData directory via rm -rf ~/Library/Developer/Xcode/DerivedData/<ProjectName>-* (found in references/stale-build-triage.md).
  • Recommends using the dangerouslyDisableSandbox: true flag for xcodebuild to bypass build sandbox restrictions when necessary (found in SKILL.md).
  • Employs security, codesign, and plutil to inspect application entitlements and provisioning profiles.
  • [EXTERNAL_DOWNLOADS]: The skill references documentation and configuration files from well-known and trusted sources.
  • Fetches tool configurations and documentation from Sentry's official GitHub repository (getsentry/XcodeBuildMCP).
  • References official Apple documentation and release notes for Xcode and iOS platform features.
  • Points to established community forums and technical blogs for concurrency debugging research.
  • [INDIRECT_PROMPT_INJECTION]: The skill identifies a potential attack surface by ingesting runtime data from a running application.
  • Ingestion points: Ingests simulator logs through simctl log stream and captures UI hierarchy and screenshots using XcodeBuildMCP (described in SKILL.md).
  • Boundary markers: Absent; the instructions do not specify delimiters for separating log content from agent instructions.
  • Capability inventory: Includes file system modification (deleting cache directories), compilation (xcodebuild), and binary execution (simctl).
  • Sanitization: Absent; the skill does not include specific guidance for sanitizing or escaping runtime log data before interpretation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:07 PM
Security Audit — agent-trust-hub — software-ios-runtime-debugging