app-store-optimization

Pass

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill's instructions in SKILL.md and documentation in README.md provide legitimate task-oriented guidance without attempting to override agent safety protocols, disregard system instructions, or activate unrestricted modes. Examples provided in HOW_TO_USE.md are benign and standard for ASO workflows.
  • [DATA_EXFILTRATION]: No patterns of sensitive data access or exfiltration were detected. The Python scripts process data provided within the agent's context and do not attempt to read sensitive files (e.g., .ssh, .aws) or hardcode any API keys or credentials. No network exfiltration calls (e.g., curl, requests) are present.
  • [SAFE]: No obfuscation techniques, including multi-layer Base64, zero-width characters, or homoglyph substitutions, were found in any of the skill files. The Python code is clearly written and documented.
  • [EXTERNAL_DOWNLOADS]: The skill README explicitly states that no external packages are required, and the scripts (keyword_analyzer.py, metadata_optimizer.py, etc.) import only modules from the Python standard library (e.g., math, re, collections, datetime). There are no remote script executions or automated installations.
  • [COMMAND_EXECUTION]: The skill does not perform any high-privilege commands (e.g., sudo), system configuration changes, or persistence-related operations. All Python modules are limited to data processing and logical calculations.
  • [SAFE]: Surface analysis for indirect prompt injection (Category 8): 1. Ingestion points: The skill ingests user-supplied reviews and app descriptions via review_analyzer.py and keyword_analyzer.py. 2. Boundary markers: Absent in the script logic. 3. Capability inventory: No dangerous capabilities such as subprocess execution, file system modification, or network requests are present in any scripts. 4. Sanitization: The scripts use basic regex-based cleaning (e.g., stripping non-alphanumeric characters) during processing. Given the absence of dangerous capabilities to exploit, this attack surface is assessed as safe.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 11, 2026, 06:20 PM
Security Audit — agent-trust-hub — app-store-optimization