ios-memgraph-leaks

Pass

Audited by Gen Agent Trust Hub on Jun 14, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local commands using standard Apple developer utilities (leaks, xcrun simctl) to debug iOS applications.
  • The shell script scripts/capture_sim_memgraph.sh properly quotes variables and uses set -euo pipefail to ensure robust and safe execution.
  • The Python script scripts/summarize_memgraph_leaks.py uses subprocess.run with a list of arguments, which is the recommended practice to avoid shell interpolation and command injection vulnerabilities.
  • [PROMPT_INJECTION]: The skill parses and summarizes output from memory analysis tools which may contain strings (such as class names) from the target application being debugged, creating a surface for indirect prompt injection.
  • Ingestion points: scripts/summarize_memgraph_leaks.py processes raw output from the leaks utility.
  • Boundary markers: The script wraps tool output within triple-tilde (~~~text) code blocks in the generated markdown report to ensure the agent treats the content as data rather than instructions.
  • Capability inventory: The skill facilitates capturing and reading memory graphs via local system commands.
  • Sanitization: The script extracts specific fields via regex while preserving the structural integrity of the report, minimizing the risk of instructions being interpreted as valid commands.
  • [SAFE]: No network operations, sensitive file access (such as credentials or SSH keys), or obfuscation techniques were identified in the skill files.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 14, 2026, 08:47 PM
Security Audit — agent-trust-hub — ios-memgraph-leaks