mapkit
Pass
Audited by Gen Agent Trust Hub on Apr 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill's SKILL.md file contains instructions to fetch supplementary documentation from sosumi.ai. This domain is a well-known community mirror used to provide Apple developer documentation in Markdown format.
- [PROMPT_INJECTION]: The skill identifies a potential surface for indirect prompt injection by directing the agent to ingest content from an external, third-party source (sosumi.ai). * Ingestion points: Agent fetching external URLs as instructed in SKILL.md. * Boundary markers: No explicit delimiters or instructions to ignore embedded commands are provided for the fetched content. * Capability inventory: This skill is documentation-only and does not include scripts, subprocess calls, or other executable capabilities. * Sanitization: No sanitization or validation of the remote documentation content is defined.
Audit Metadata