expo-react-native-review
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides purely instructional content for performing code reviews on mobile applications. It correctly identifies security risks such as hardcoded secrets, unsafe storage of tokens, and improper deep link handling as review findings, promoting best practices without introducing its own risks.- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted external data such as repository code, lockfiles, and build logs. This creates a standard attack surface for indirect prompt injection where malicious code could attempt to influence the agent's review. However, the skill provides no dangerous capabilities or autonomous tools that could be exploited via this surface. Ingestion points: repo files, lockfiles, app configuration, and EAS logs. Boundary markers: None. Capability inventory: None (instructional markdown only). Sanitization: Not explicitly mentioned in instructions.
Audit Metadata