Back to skill

Security audit

Ios Dev Skill

Security checks across malware telemetry and agentic risk

Overview

This is a read-only Swift and iOS development reference skill with no executable code, hidden data access, or install-time behavior.

Install this as a documentation/reference skill for Swift and iOS development. Be aware that it may activate broadly for Swift-related questions and may prefer Chinese-style structured answers, so users may need to explicitly request another language or format.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger and description are extremely broad, covering nearly any Swift-, iOS-, UIKit-, or Xcode-related prompt. In an agent environment, this can cause the skill to activate outside its narrow intended scope and override more appropriate system behavior or other safer, more specialized skills, increasing the chance of instruction hijacking or irrelevant skill injection.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The skill hard-codes an output format in Chinese without considering the user's language or system preferences. This can interfere with higher-priority instructions, degrade usability, and in some agent contexts cause policy or task-completion failures when the user expects another language.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.