mapkit
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied search queries through autocomplete and search APIs. \n
- Ingestion points: The
queryfragment inSearchCompleter(SKILL.md) andsearchTextinMapSearchView(references/mapkit-patterns.md).\n - Boundary markers: Not explicitly implemented for the search strings.\n
- Capability inventory: Utilizes
MKLocalSearchandMKLocalSearchCompleterfor network-based location lookups.\n - Sanitization: Includes debouncing (300ms) to throttle input processing.\n- [METADATA_POISONING]: The skill includes documentation links targeting 'sosumi.ai' and refers to a non-existent 'iOS 26' version. These items appear to be placeholders or illustrative examples rather than attempts to deceive the agent for malicious purposes.
Audit Metadata