expo-tailwind-setup-v55
Fail
Audited by Gen Agent Trust Hub on Aug 30, 2026
Risk Level: CRITICALREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill instructs the user to run
npx --yes submit-expo-feedback@latestto provide feedback. This command downloads and executes arbitrary code from a package that is not part of the official Expo toolchain nor affiliated with the skill's author ('blockmatic'). Executing unverified packages with 'latest' tags is a common vector for distributing malicious payloads. - [EXTERNAL_DOWNLOADS]: The installation instructions require several Node.js packages including specific nightly builds (
react-native-css@0.0.0-nightly.5ce6396) and preview versions. While these may be required for cutting-edge features, they introduce risks from unverified code origins and potential supply chain vulnerabilities.
Recommendations
- AI detected serious security threats
Audit Metadata