xcodebuildmcp-rendering-streaming-review
Pass
Audited by Gen Agent Trust Hub on Apr 28, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill instructions are focused on code review and architectural adherence, with no evidence of malicious intent or behavior.\n- [COMMAND_EXECUTION]: Includes standard validation commands such as
npm testandnpm run typecheckto verify code changes. These are typical for developer-focused skills and are executed in the local project context.\n- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to inspect documentation hosted onxcodebuildmcp.com. These are project-specific resources used for reference during the review process.\n- [PROMPT_INJECTION]: The skill has a surface for indirect prompt injection as it processes data from local source files and external documentation.\n - Ingestion points: Local files in
src/and external documents fromxcodebuildmcp.com.\n - Boundary markers: No delimiters or ignore instructions are present for the ingested data.\n
- Capability inventory: Shell command execution via
npmandnpx.\n - Sanitization: No sanitization or validation of the ingested content is specified.
Audit Metadata