native-sdk
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill guides users to install the
@native-sdk/clipackage from the public NPM registry as part of the initial setup. - [COMMAND_EXECUTION]: The skill utilizes the
nativecommand-line tool to initialize projects (native init), manage development servers (native dev), and retrieve specialized skill modules via the CLI. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and follow instructions fetched at runtime via the
native skills getcommand suite. - Ingestion points: Reference documentation, implementation guides, and orientation content retrieved from
native skills get core,native skills get automation, andnative skills get zigcommands. - Boundary markers: No specific delimiters or warnings to ignore embedded instructions are present in the discovery stub.
- Capability inventory: The skill is scoped to execute subcommands of the
nativeCLI tool and the@native-sdk/clipackage via npx. - Sanitization: Content is retrieved through the SDK's own command-line utility, representing standard documentation delivery for the toolkit.
Audit Metadata