develop-macos-liquid-glass
Pass
Audited by Gen Agent Trust Hub on Apr 7, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is composed exclusively of instructional Markdown files intended to guide an AI agent in reviewing and generating SwiftUI/AppKit code according to a specific design system. There are no executable scripts, binaries, or configuration files that could pose a direct security risk.
- [PROMPT_INJECTION]: While the skill adopts a specific persona ('senior Apple design engineer'), it does not employ malicious prompt injection techniques designed to bypass safety filters or extract system prompts. The instructions are focused on design logic and code transformation.
- [DATA_EXFILTRATION]: No network operations (e.g.,
curl,wget) or access to sensitive local file paths (e.g.,.ssh,.env) are present in the skill content. - [REMOTE_CODE_EXECUTION]: There are no patterns suggesting the download or execution of remote code. All referenced tools and APIs (such as 'Xcode 26') are part of the fictional context of the skill.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process and transform user-provided SwiftUI code. While this constitutes an attack surface for indirect prompt injection (Category 8), the skill itself does not contain malicious payloads and lacks dangerous tool-use capabilities that could be exploited via such an injection. The behavior is inherent to the skill's primary purpose of code analysis and modernization.
Audit Metadata