signing-entitlements

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [Indirect Prompt Injection Surface]: The skill is designed to analyze external, potentially untrusted artifacts such as application bundles, binaries, and configuration files. This creates a surface where instructions embedded in file metadata or content could potentially influence agent behavior.
  • Ingestion points: The skill reads .app bundles, binary executables, and .plist files from the local filesystem to diagnose issues.
  • Boundary markers: The instructions do not define specific delimiters or instructions to ignore content within the analyzed files.
  • Capability inventory: The skill utilizes shell-based system utilities including codesign, spctl, security, and plutil to perform inspections.
  • Sanitization: There is no explicit sanitization or validation of the content being parsed by the diagnostic tools.
  • [System Utility Execution]: The skill employs standard macOS security and inspection tools (codesign, spctl, security, plutil) to diagnose environment issues. While these are appropriate for the skill's diagnostic purpose, they involve executing commands that interact with the system's security posture and identity database.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 04:16 PM
Security Audit — agent-trust-hub — signing-entitlements