ios-development

Pass

Audited by Gen Agent Trust Hub on Feb 27, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill's UI review module utilizes the WebFetch tool to retrieve current platform guidelines from official Apple documentation at developer.apple.com. This is a legitimate and neutral use of external resources to ensure compliance with the Human Interface Guidelines.
  • [PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection because it is designed to ingest and analyze untrusted content from local codebases and the web. Since it also has Write tool permissions to generate documentation, malicious instructions hidden in the analyzed data (e.g., in code comments or metadata) could theoretically influence the agent's behavior during the planning or review processes.
  • [SAFE]: No evidence of hardcoded credentials, obfuscation, unauthorized command execution, or data exfiltration was found. The skill's metadata and instructional content are consistent with its stated purpose of providing development guidance.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 27, 2026, 04:35 PM