senior-mobile
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill instructions and associated scripts do not contain any malicious behavior. All scripts are written in Python using standard libraries and focus on local file manipulation for project scaffolding and static analysis.
- [COMMAND_EXECUTION]: The skill utilizes local scripts such as
mobile_scaffold.pyandapp_performance_analyzer.py. These tools are designed for project initialization and code quality checks. They do not incorporate untrusted external input into shell commands or execute arbitrary code from remote sources. - [DATA_EXFILTRATION]: Analysis of the provided Python scripts confirms a total absence of network-related libraries (e.g.,
requests,urllib,socket). The tools operate strictly within the local file system, ensuring that project data and metadata are not transmitted externally. - [INDIRECT_PROMPT_INJECTION]: The
app_performance_analyzer.pyscript identifies an ingestion surface as it reads and analyzes local source code files. However, it employs static regex-based pattern matching to detect performance issues and does not interpret or execute the content of the files, mitigating the risk of injection attacks. - [CREDENTIALS_SAFE]: The skill includes high-quality documentation in
references/mobile-security-guide.mdwhich educates users on secure storage practices using platform-native APIs like iOS Keychain and Android Keystore, while explicitly warning against hardcoding credentials.
Audit Metadata