hmos-push-kit-background
Pass
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides legitimate development templates and instructions for HMS Push Kit integration. All referenced endpoints and kits (e.g., @kit.PushKit) are standard HarmonyOS components. No unauthorized exfiltration, malicious command execution, or obfuscation was found.
- [PROMPT_INJECTION]: The skill includes instructions for the agent to scan project files to detect existing Push Kit logic, which creates a potential surface for indirect prompt injection. Ingestion points: Reads project files such as EntryAbility.ets and module.json5 during the automated detection phase. Boundary markers: No delimiters or 'ignore' instructions are specified for the processed content. Capability inventory: The skill allows the agent to create and modify source code and manifest files. Sanitization: No filtering or sanitization logic is provided for data read from user files.
Audit Metadata