squad-mobile
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to handle external data that could contain malicious instructions, such as API responses, deep-link parameters, and push notification payloads.
- Ingestion points: Untrusted data enters the agent's context through API integration, deep-link handling, and push notifications as specified in
SKILL.md. - Boundary markers: The skill includes explicit instructions to "Treat API/deep-link/push payloads as untrusted" and to "validate all external payloads."
- Capability inventory: The agent has the authority to write code, implement network logic, and execute build and test commands.
- Sanitization: Instructions prioritize validation and state that client-side checks should not be treated as security boundaries.
- [SAFE]: The skill demonstrates several security-positive patterns.
- It mandates the use of platform-specific secure storage (Keychain/Keystore) for credentials.
- It explicitly forbids the logging of secrets, tokens, or personal data and requires redaction in crash reports.
- It includes a strict rule in
references/runtime-capability-fallbacks.mdagainst the automatic installation of skills, SDKs, packages, or native modules, which mitigates supply chain and remote code execution risks.
Audit Metadata