expo-tailwind-setup

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to install several Node.js dependencies. A specific dependency, react-native-css@0.0.0-nightly.5ce6396, appears to be a non-standard package name for the functionality described (styling runtime for NativeWind v5, which typically uses react-native-css-interop). This discrepancy poses a risk of package confusion or installation failure.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides instructions for the agent to modify project configuration files (Metro, PostCSS, and global CSS). While this is the intended functionality of a setup skill, it defines a broad capability set that could be exploited if the agent were to process untrusted external data in the same context, though no specific exploitation vector is present in the skill itself.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 10:54 AM
Security Audit — agent-trust-hub — expo-tailwind-setup