app-store-optimization

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it ingests and processes untrusted data from external sources, such as user reviews and competitor app descriptions.
  • Ingestion points: The review_analyzer.py script processes lists of review text, and competitor_analyzer.py processes competitor metadata. These inputs are typically sourced from public app stores.
  • Boundary markers: The skill does not implement boundary markers (delimiters) or explicit instructions for the agent to ignore embedded commands when returning processed external content to the agent's context.
  • Capability inventory: A review of all scripts (ab_test_planner.py, aso_scorer.py, competitor_analyzer.py, keyword_analyzer.py, launch_checklist.py, localization_helper.py, metadata_optimizer.py, and review_analyzer.py) confirms there are no high-risk capabilities such as network access, file writing, or subprocess execution. This lack of sensitive tools effectively mitigates the potential impact of an indirect injection attack.
  • Sanitization: While some functions in review_analyzer.py use regex to clean text for frequency analysis, raw snippets of reviews are still passed back to the agent in fields like text_preview and examples without sanitization against prompt injection patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 05:45 AM
Security Audit — agent-trust-hub — app-store-optimization