expo-motion
Pass
Audited by Gen Agent Trust Hub on Aug 25, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill includes instructions for the user to install and execute a local auditing tool via 'cargo install --path crates/expo-motion-audit'.
- [INDIRECT_PROMPT_INJECTION]: The skill analyzes project files such as 'package.json' and 'app.json', creating an indirect prompt injection surface. Ingestion points: Project configuration and source files. Boundary markers: None specified for file reading. Capability inventory: Automated configuration analysis and implementation guidance. Sanitization: No specific filtering of file content is mentioned.
Audit Metadata