aso-audit
Pass
Audited by Gen Agent Trust Hub on Apr 16, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns, such as command injection, obfuscation, or credential exfiltration, were detected in any of the skill files.
- [EXTERNAL_DOWNLOADS]: The skill identifies and fetches data from well-known app store domains (apps.apple.com and play.google.com) to extract metadata and visual assets for analysis. This behavior is restricted to the primary purpose of the skill.
- [DATA_EXPOSURE]: The skill requests to read project context from
.agents/product-marketing-context.mdor.claude/product-marketing-context.md. This is a standard practice for project-aware AI assistants to avoid repetitive questioning and provide more relevant audits. - [PROMPT_INJECTION]: The skill processes untrusted external data (app titles and descriptions), creating an inherent surface for indirect prompt injection. However, the skill instructions are focused on specific data extraction and scoring against a set of rubrics, which limits the potential impact of such injections.
Audit Metadata