app-intents

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill defines implementation patterns for Visual Intelligence and Spotlight search that ingest external, untrusted data.\n
  • Ingestion points: IntentValueQuery in SKILL.md and references/system-surfaces.md processes SemanticContentDescriptor inputs, including text-based labels and image buffers.\n
  • Boundary markers: The instructions do not specify the use of delimiters or boundary markers to isolate external descriptors from the intent execution logic.\n
  • Capability inventory: The intent protocols described (AppIntent, SetValueIntent) have the capability to perform state-changing operations such as processing orders or controlling devices via the perform() method.\n
  • Sanitization: There are no explicit instructions for sanitizing or validating external labels before they are used in query logic or returned as results.\n- [EXTERNAL_DOWNLOADS]: The skill repeatedly references documentation and API details hosted on a third-party domain (sosumi.ai) instead of official Apple developer resources.\n
  • Evidence: References to documentation for IntentParameter, IntentCollectionSize, and other framework members in references/appintents-advanced.md and references/system-surfaces.md utilize the sosumi.ai domain.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 03:41 PM
Security Audit — agent-trust-hub — app-intents