mobile-design

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes a specialized Python script (scripts/mobile_audit.py) designed to be executed by the agent to perform static analysis on mobile project codebases. The script checks for UX issues, performance anti-patterns, and insecure storage practices using standard Python libraries and regex pattern matching.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted external data in the form of user-provided source code files. While this represents a theoretical attack surface for indirect prompt injection, the risk is mitigated because the analysis is performed via static regex matching rather than dynamic execution or direct interpolation into the agent's primary reasoning loop.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 02:32 PM
Security Audit — agent-trust-hub — mobile-design