mobile-design
Pass
Audited by Gen Agent Trust Hub on Aug 14, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill documentation is purely instructional and lacks any attempts to override model safety or bypass system prompts.
- [DATA_EXPOSURE_AND_EXFILTRATION]: No sensitive data access or network exfiltration logic is present; the guidelines actively promote secure storage of authentication tokens.
- [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: The included diagnostic script is a self-contained Python utility that performs static regex-based analysis without executing target code or fetching remote dependencies.
- [COMMAND_EXECUTION]: Authorized tools like Bash are used appropriately for running the provided audit utility, with no dangerous command patterns found.
- [INDIRECT_PROMPT_INJECTION]: The tool surface involves reading local project files, but the lack of network access or execution capabilities prevents this from being a viable attack vector.
Audit Metadata