app-store-optimization

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill's primary functionality is implemented through local Python scripts (scripts/*.py) that perform text analysis and statistical calculations using only the Python standard library.
  • [SAFE]: No network-enabled operations (e.g., curl, wget, requests) were found in any of the skill's scripts or documentation, ensuring that user data remains local.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data such as user reviews and competitor app descriptions.
  • Ingestion points: Untrusted data enters the context through review_analyzer.py (reviews) and competitor_analyzer.py (competitor metadata).
  • Boundary markers: The skill does not employ specific boundary markers or 'ignore' instructions for the processed data.
  • Capability inventory: Analysis of all scripts confirms zero capabilities for subprocess execution, network requests, file writes, or dynamic code evaluation.
  • Sanitization: Standard text cleaning (lowercasing, punctuation removal) is performed, but no formal sanitization for prompt injection is present. However, given the complete lack of dangerous capabilities, this surface area presents no significant risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 02:45 PM
Security Audit — agent-trust-hub — app-store-optimization