expo-security-permissions
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill is a collection of educational and instructional guidelines for performing security reviews. It adheres to mobile security best practices, such as recommending OAuth with PKCE, SecureStore for sensitive tokens, and strict validation of deep links and WebView origins.
- [INDIRECT_PROMPT_INJECTION]: The skill's primary purpose is to ingest and analyze external codebases (Expo/React Native repositories). This creates a potential surface for indirect prompt injection where malicious instructions inside a project being reviewed could attempt to influence the agent. However, because the skill is instructional and does not grant the agent automated capabilities to execute code or write to the filesystem based on that data, the risk remains within safe limits.
- Ingestion points: Processes for repo detection and analysis described in SKILL.md.
- Boundary markers: None explicitly defined in the instructions.
- Capability inventory: The skill is restricted to instructional logic; no tools for remote code execution, network exfiltration, or filesystem modification are invoked.
- Sanitization: Not applicable as the skill does not interpolate untrusted data into sensitive commands.
- [SAFE]: No evidence of obfuscation, hardcoded credentials, or unauthorized network operations was found. The reference to
itsol-current-tech-contextaligns with the author's identity and represents a standard extension for technical documentation retrieval.
Audit Metadata