expo-tailwind-setup
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to install several Node.js dependencies. A specific dependency,
react-native-css@0.0.0-nightly.5ce6396, appears to be a non-standard package name for the functionality described (styling runtime for NativeWind v5, which typically usesreact-native-css-interop). This discrepancy poses a risk of package confusion or installation failure. - [INDIRECT_PROMPT_INJECTION]: The skill provides instructions for the agent to modify project configuration files (Metro, PostCSS, and global CSS). While this is the intended functionality of a setup skill, it defines a broad capability set that could be exploited if the agent were to process untrusted external data in the same context, though no specific exploitation vector is present in the skill itself.
Audit Metadata