ios-development
Pass
Audited by Gen Agent Trust Hub on Feb 27, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill's UI review module utilizes the
WebFetchtool to retrieve current platform guidelines from official Apple documentation atdeveloper.apple.com. This is a legitimate and neutral use of external resources to ensure compliance with the Human Interface Guidelines. - [PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection because it is designed to ingest and analyze untrusted content from local codebases and the web. Since it also has
Writetool permissions to generate documentation, malicious instructions hidden in the analyzed data (e.g., in code comments or metadata) could theoretically influence the agent's behavior during the planning or review processes. - [SAFE]: No evidence of hardcoded credentials, obfuscation, unauthorized command execution, or data exfiltration was found. The skill's metadata and instructional content are consistent with its stated purpose of providing development guidance.
Audit Metadata