harmonyos-dev

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists entirely of instructional documentation and reference materials for HarmonyOS development. It does not contain executable code, installation scripts, or automated network operations. The content specifically promotes security best practices, such as using parameterized queries to prevent SQL injection and applying the principle of least privilege for system permissions.
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to read repository configuration files (e.g., build-profile.json5, module.json5) to establish project context. While this is an ingestion surface for untrusted data, the instructions are strictly limited to deriving technical metadata like SDK versions and device constraints, and the agent is explicitly told to verify information against official documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 12:52 PM
Security Audit — agent-trust-hub — harmonyos-dev