swift-concurrency
Pass
Audited by Gen Agent Trust Hub on Apr 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to fetch additional documentation from 'sosumi.ai', an unofficial community mirror of Apple's developer documentation, when information is not found locally.
- [PROMPT_INJECTION]: The use of an external documentation source provides a surface for indirect prompt injection.
- Ingestion points: Markdown content retrieved from 'sosumi.ai' (as directed in SKILL.md).
- Boundary markers: Absent; fetched content is not delimited or marked as untrusted.
- Capability inventory: The agent utilizes the content to generate technical explanations and code snippets.
- Sanitization: Absent; the skill does not verify the integrity or safety of the fetched documentation.
Audit Metadata