app-intents
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines implementation patterns for Visual Intelligence and Spotlight search that ingest external, untrusted data.\n
- Ingestion points:
IntentValueQueryinSKILL.mdandreferences/system-surfaces.mdprocessesSemanticContentDescriptorinputs, including text-based labels and image buffers.\n - Boundary markers: The instructions do not specify the use of delimiters or boundary markers to isolate external descriptors from the intent execution logic.\n
- Capability inventory: The intent protocols described (
AppIntent,SetValueIntent) have the capability to perform state-changing operations such as processing orders or controlling devices via theperform()method.\n - Sanitization: There are no explicit instructions for sanitizing or validating external labels before they are used in query logic or returned as results.\n- [EXTERNAL_DOWNLOADS]: The skill repeatedly references documentation and API details hosted on a third-party domain (
sosumi.ai) instead of official Apple developer resources.\n - Evidence: References to documentation for
IntentParameter,IntentCollectionSize, and other framework members inreferences/appintents-advanced.mdandreferences/system-surfaces.mdutilize thesosumi.aidomain.
Audit Metadata