mobile-design
Pass
Audited by Gen Agent Trust Hub on Mar 18, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a collection of design guidelines and a local audit tool. No malicious code or exfiltration patterns were detected across the 14 files.
- [COMMAND_EXECUTION]: The skill includes a Python script
scripts/mobile_audit.pyintended for auditing mobile project files. Analysis of the script shows it uses standard Python libraries (os,re,pathlib,json) to perform static analysis via regular expressions. It does not execute the code it reads, nor does it perform network operations or access sensitive system files. - [PROMPT_INJECTION]: The documentation uses strong instructional language (e.g., "ANTI-MEMORIZATION", "FORBIDDEN LIST", "MANDATORY") to ensure the AI follows specific design principles rather than relying on training defaults. These are task-oriented behavioral constraints and do not represent attempts to bypass safety filters or extract system prompts.
- [DATA_EXFILTRATION]: No network calls (
curl,wget,requests, etc.) or hardcoded credentials were found. The skill's primary function is processing local project files for UX auditing, which is performed entirely locally. - [INDIRECT_PROMPT_INJECTION]: While the
mobile_audit.pyscript ingests untrusted data (user-provided mobile code), its capabilities are strictly limited to printing analysis results to stdout. It lacks the primitives (exec, eval, network, or file-write) required to turn malicious input into a compromise.
Audit Metadata