mobile-design

Pass

Audited by Gen Agent Trust Hub on Mar 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a collection of design guidelines and a local audit tool. No malicious code or exfiltration patterns were detected across the 14 files.
  • [COMMAND_EXECUTION]: The skill includes a Python script scripts/mobile_audit.py intended for auditing mobile project files. Analysis of the script shows it uses standard Python libraries (os, re, pathlib, json) to perform static analysis via regular expressions. It does not execute the code it reads, nor does it perform network operations or access sensitive system files.
  • [PROMPT_INJECTION]: The documentation uses strong instructional language (e.g., "ANTI-MEMORIZATION", "FORBIDDEN LIST", "MANDATORY") to ensure the AI follows specific design principles rather than relying on training defaults. These are task-oriented behavioral constraints and do not represent attempts to bypass safety filters or extract system prompts.
  • [DATA_EXFILTRATION]: No network calls (curl, wget, requests, etc.) or hardcoded credentials were found. The skill's primary function is processing local project files for UX auditing, which is performed entirely locally.
  • [INDIRECT_PROMPT_INJECTION]: While the mobile_audit.py script ingests untrusted data (user-provided mobile code), its capabilities are strictly limited to printing analysis results to stdout. It lacks the primitives (exec, eval, network, or file-write) required to turn malicious input into a compromise.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 18, 2026, 07:46 AM
Security Audit — agent-trust-hub — mobile-design