react-native-expert
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill presents a potential vulnerability surface as it instructs the agent to process external application code and execute development commands, which is inherent to its primary purpose as a mobile engineering assistant.
- Ingestion points: Mobile application source code (components, hooks, services) and configuration files (app.json, package.json).
- Boundary markers: None identified in the instructional body for separating untrusted project data from agent instructions.
- Capability inventory: Execution of shell commands via the Expo CLI (
npx expo doctor,npx expo run:ios, etc.), file system read/write access for project organization, and network operations via standard mobile API development. - Sanitization: No explicit sanitization or validation of project-file content is specified before processing or executing commands.
- [COMMAND_EXECUTION]: The skill recommends using standard Expo and React Native CLI tools. These commands are localized to the development environment and represent standard workflows for mobile app development.
- Evidence:
npx expo doctor,npx expo start --clear,npx expo run:ios,npx expo run:android. - [EXTERNAL_DOWNLOADS]: The skill lists standard, well-known libraries for React Native development in the project structure reference. These packages originate from official registries and are essential for the stated functionality.
- Evidence: Dependencies include
expo,expo-router,react-native-reanimated, andzustand.
Audit Metadata