verified-email

Warn

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSPROMPT_INJECTIONSAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill metadata falsely identifies the author as 'Google LLC', while the skill is provided by 'IsKenKenYa'. This impersonation is deceptive and could lead users to attribute a higher level of trust to the content than is warranted based on a falsified identity.
  • [EXTERNAL_DOWNLOADS]: The skill contains references to external documentation and sample repositories including 'github.com/android/identity-samples', 'github.com/digitalcredentialsdev/CMWallet', and 'github.com/deephand/webauthn-in-webview' for implementation demonstrations.
  • [SAFE]: The technical instructions and code snippets correctly follow Android security best practices for identity management, specifically emphasizing the necessity of server-side validation and the use of cryptographically secure nonces.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 22, 2026, 10:16 AM
Security Audit — agent-trust-hub — verified-email