expo-app-clip
Fail
Audited by Gen Agent Trust Hub on Aug 14, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONDATA_EXFILTRATIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill directs the agent to execute multiple remote packages via
npxandbunx, includingsetup-safari,testflight, andsubmit-expo-feedback. These packages are executed without version pinning (using@latest) or organization-level scoping (e.g.,@expo/), which allows for the execution of arbitrary code fetched at runtime. - [DATA_EXFILTRATION]: A telemetry command
submit-expo-feedbackis included to transmit user-provided feedback and context to a remote server. This pattern can be abused to exfiltrate sensitive project information under the guise of feedback. - [COMMAND_EXECUTION]: The skill uses the
setup-safariutility to log into Apple Developer accounts and perform administrative actions. This involves passing sensitive developer credentials through an unverified third-party tool. - [EXTERNAL_DOWNLOADS]: The skill references documentation hosted on
sosumi.aiinstead of official Apple or Expo developer portals. Unofficial domains for technical specifications can be used to host malicious instructions or phishing links.
Recommendations
- AI detected serious security threats
Audit Metadata