upgrading-react-native
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches React Native template diffs, release information, and Gradle wrapper binaries from the official react-native-community GitHub organization. These resources are industry-standard for managing React Native version transitions.
- [COMMAND_EXECUTION]: Utilizes standard toolchain commands including npm, npx, CocoaPods (pod install), and native build tools (xcodebuild, gradle) to perform dependency updates and verify the success of the upgrade process.
- [PRIVILEGE_ESCALATION]: Uses sudo for administrative environment configuration, specifically targeting xcode-select and xcodebuild setup. This is a standard prerequisite for ensuring the iOS build toolchain is correctly synchronized on macOS development machines.
- [INDIRECT_PROMPT_INJECTION]:
- Ingestion points: Reads project package.json files and external diff files from the rn-diff-purge repository.
- Boundary markers: None explicitly defined in instructions, though the skill relies on standard developer tools for comparison and application.
- Capability inventory: Perform file modifications (applying diffs), package installation (npm/yarn/pnpm), and native project compilation.
- Sanitization: Uses grep to inspect diff content prior to application to ensure structural integrity.
Audit Metadata