hmos-push-kit-background

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides legitimate development templates and instructions for HMS Push Kit integration. All referenced endpoints and kits (e.g., @kit.PushKit) are standard HarmonyOS components. No unauthorized exfiltration, malicious command execution, or obfuscation was found.
  • [PROMPT_INJECTION]: The skill includes instructions for the agent to scan project files to detect existing Push Kit logic, which creates a potential surface for indirect prompt injection. Ingestion points: Reads project files such as EntryAbility.ets and module.json5 during the automated detection phase. Boundary markers: No delimiters or 'ignore' instructions are specified for the processed content. Capability inventory: The skill allows the agent to create and modify source code and manifest files. Sanitization: No filtering or sanitization logic is provided for data read from user files.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 10:16 AM
Security Audit — agent-trust-hub — hmos-push-kit-background