cloudkit
Warn
Audited by Gen Agent Trust Hub on Feb 16, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS] (MEDIUM): The installation instructions in the README.md recommend cloning a repository from an untrusted source (github.com/subsc-taha/cloudkit-skill). This source is not within the defined trusted organizations and requires thorough review of all contents before adoption.
- [Metadata Poisoning] (MEDIUM): The references/troubleshooting.md file contains specific technical fixes for iOS 26. Since the current iOS version is significantly lower, this indicates the documentation contains misleading or hallucinatory metadata that can degrade the reliability of an AI agent's output.
- [Indirect Prompt Injection] (LOW): This documentation-based skill serves as a large body of external content intended to influence agent reasoning. 1. Ingestion points: All provided Markdown reference files. 2. Boundary markers: Absent. 3. Capability inventory: No executable scripts or direct system calls were found in the provided documentation snippets. 4. Sanitization: Absent. The skill provides an attack surface where an agent could potentially be misled by unverified external instructions.
Audit Metadata