expo-react-native-debugging

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to use standard development CLI tools such as npx expo-doctor, npx expo start, npx expo prebuild, and eas build. These are well-known, legitimate tools within the React Native and Expo ecosystems for diagnosing project health and managing build pipelines.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill explicitly includes security-focused instructions regarding data hygiene. It advises against logging sensitive information such as tokens, passwords, private keys, or PII. It also recommends using SecureStore for session tokens instead of insecure storage, which aligns with industry best practices for mobile application security.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a process for ingesting external evidence such as crash logs, Metro output, and API request data. While this creates an ingestion surface for untrusted data, the skill includes explicit instructions for data hygiene and evidence classification, and the agent's role is restricted to technical analysis and debugging advice rather than automated execution based on input data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 02:30 PM
Security Audit — agent-trust-hub — expo-react-native-debugging