expo-app-clip

Fail

Audited by Gen Agent Trust Hub on Aug 14, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONDATA_EXFILTRATIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill directs the agent to execute multiple remote packages via npx and bunx, including setup-safari, testflight, and submit-expo-feedback. These packages are executed without version pinning (using @latest) or organization-level scoping (e.g., @expo/), which allows for the execution of arbitrary code fetched at runtime.
  • [DATA_EXFILTRATION]: A telemetry command submit-expo-feedback is included to transmit user-provided feedback and context to a remote server. This pattern can be abused to exfiltrate sensitive project information under the guise of feedback.
  • [COMMAND_EXECUTION]: The skill uses the setup-safari utility to log into Apple Developer accounts and perform administrative actions. This involves passing sensitive developer credentials through an unverified third-party tool.
  • [EXTERNAL_DOWNLOADS]: The skill references documentation hosted on sosumi.ai instead of official Apple or Expo developer portals. Unofficial domains for technical specifications can be used to host malicious instructions or phishing links.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Aug 14, 2026, 01:43 PM
Security Audit — agent-trust-hub — expo-app-clip