Back to skill

Security audit

App Intents Code Review

Security checks for vulnerabilities and agentic risk

Overview

The skill is a markdown-only App Intents code-review guide, but it relies on an unaudited external checklist that could change or suppress review findings.

Install only if you are comfortable with this skill depending on a neighboring review-verification-protocol skill. Before relying on its reviews, make sure that external protocol is present, trusted, versioned, and cannot silently override or suppress findings.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:45
Finding

External Instruction Dependency Can Hijack and Suppress Audit Findings

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The 'Multilingual Considerations' section instructs developers to test with Siri language matching app language settings and focus on region-specific variations. This can be read as enforcing a specific language/locale alignment rather than explicitly supporting user choice, which may conflict with language/locale policy expectations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.