upgrading-react-native

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches React Native template diffs, release information, and Gradle wrapper binaries from the official react-native-community GitHub organization. These resources are industry-standard for managing React Native version transitions.
  • [COMMAND_EXECUTION]: Utilizes standard toolchain commands including npm, npx, CocoaPods (pod install), and native build tools (xcodebuild, gradle) to perform dependency updates and verify the success of the upgrade process.
  • [PRIVILEGE_ESCALATION]: Uses sudo for administrative environment configuration, specifically targeting xcode-select and xcodebuild setup. This is a standard prerequisite for ensuring the iOS build toolchain is correctly synchronized on macOS development machines.
  • [INDIRECT_PROMPT_INJECTION]:
  • Ingestion points: Reads project package.json files and external diff files from the rn-diff-purge repository.
  • Boundary markers: None explicitly defined in instructions, though the skill relies on standard developer tools for comparison and application.
  • Capability inventory: Perform file modifications (applying diffs), package installation (npm/yarn/pnpm), and native project compilation.
  • Sanitization: Uses grep to inspect diff content prior to application to ensure structural integrity.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 11:37 AM
Security Audit — agent-trust-hub — upgrading-react-native