app-store-optimization
Pass
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it ingests and processes untrusted data from external sources, such as user reviews and competitor app descriptions.
- Ingestion points: The
review_analyzer.pyscript processes lists of review text, andcompetitor_analyzer.pyprocesses competitor metadata. These inputs are typically sourced from public app stores. - Boundary markers: The skill does not implement boundary markers (delimiters) or explicit instructions for the agent to ignore embedded commands when returning processed external content to the agent's context.
- Capability inventory: A review of all scripts (
ab_test_planner.py,aso_scorer.py,competitor_analyzer.py,keyword_analyzer.py,launch_checklist.py,localization_helper.py,metadata_optimizer.py, andreview_analyzer.py) confirms there are no high-risk capabilities such as network access, file writing, or subprocess execution. This lack of sensitive tools effectively mitigates the potential impact of an indirect injection attack. - Sanitization: While some functions in
review_analyzer.pyuse regex to clean text for frequency analysis, raw snippets of reviews are still passed back to the agent in fields liketext_previewandexampleswithout sanitization against prompt injection patterns.
Audit Metadata