app-store-optimization
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill's primary functionality is implemented through local Python scripts (
scripts/*.py) that perform text analysis and statistical calculations using only the Python standard library. - [SAFE]: No network-enabled operations (e.g.,
curl,wget,requests) were found in any of the skill's scripts or documentation, ensuring that user data remains local. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data such as user reviews and competitor app descriptions.
- Ingestion points: Untrusted data enters the context through
review_analyzer.py(reviews) andcompetitor_analyzer.py(competitor metadata). - Boundary markers: The skill does not employ specific boundary markers or 'ignore' instructions for the processed data.
- Capability inventory: Analysis of all scripts confirms zero capabilities for subprocess execution, network requests, file writes, or dynamic code evaluation.
- Sanitization: Standard text cleaning (lowercasing, punctuation removal) is performed, but no formal sanitization for prompt injection is present. However, given the complete lack of dangerous capabilities, this surface area presents no significant risk.
Audit Metadata