verified-email
Warn
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSPROMPT_INJECTIONSAFE
Full Analysis
- [PROMPT_INJECTION]: The skill metadata falsely identifies the author as 'Google LLC', while the skill is provided by 'IsKenKenYa'. This impersonation is deceptive and could lead users to attribute a higher level of trust to the content than is warranted based on a falsified identity.
- [EXTERNAL_DOWNLOADS]: The skill contains references to external documentation and sample repositories including 'github.com/android/identity-samples', 'github.com/digitalcredentialsdev/CMWallet', and 'github.com/deephand/webauthn-in-webview' for implementation demonstrations.
- [SAFE]: The technical instructions and code snippets correctly follow Android security best practices for identity management, specifically emphasizing the necessity of server-side validation and the use of cryptographically secure nonces.
Audit Metadata