expo
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill incorporates clear security guidelines, instructing the agent to never commit keystores, certificates, or mobile provisioning profiles to the repository.
- [SAFE]: The provided
scripts/verify.shis a read-only utility script that performs local audits for security and configuration best practices. It checks for plaintext secrets in configuration files and ensures signing materials are not tracked by git. - [DYNAMIC_EXECUTION]: The
verify.shscript utilizesnode -eandpython3 -cto validate JSON syntax ineas.json. This is a routine and safe method for verifying file integrity on the local file system without executing untrusted logic. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to process configuration data from
app.jsonandeas.json. It includes mitigation measures such as theverify.shtool to audit these files for suspicious content and ensures the shipping pipeline follows strict, predefined commands (prebuild, build, submit, update).
Audit Metadata