cocoapods-to-spm
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- EXTERNAL_DOWNLOADS (LOW): The skill identifies and recommends several third-party libraries via GitHub URLs (e.g., KeychainAccess, SDWebImage, SnapKit, Realm, and nicholasalx/capacitor-swift-pm). These repositories are outside the defined trusted organization scope. However, their inclusion is directly related to the skill's primary purpose of dependency migration, leading to a downgrade from MEDIUM to LOW severity.
- COMMAND_EXECUTION (SAFE): The guide includes standard maintenance commands such as
pod deintegrate,rm -rf Pods, and cleaning Xcode'sDerivedData. These operations are appropriate for the intended use case of resetting project build states during migration.
Audit Metadata