mobile-ionic-capacitor

Warn

Audited by Gen Agent Trust Hub on Jul 8, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The file 'references/capacitor-plugins.md' contains multiple misspelled package names using the incorrect '@capacicator/' scope instead of the official '@capacitor/' scope (e.g., '@capacicator/app', '@capacicator/network', '@capacicator/screen-reader'). Following these instructions verbatim would lead to attempts to install non-existent or potentially malicious third-party dependencies.
  • [COMMAND_EXECUTION]: The skill provides instructions for executing numerous powerful CLI commands and build scripts. While these are common for hybrid mobile development, the high volume of commands combined with suspicious bloating in reference files warrants caution during execution.
  • [COMMAND_EXECUTION]: Eight reference documents (such as 'security-best-practices.md' and 'architecture-patterns.md') are highly irregular, each containing exactly 150 sections of repetitive, generic technical text. This noise injection is a deceptive structure that could be intended to exhaust an AI agent's context window or obscure other information.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 8, 2026, 12:25 PM
Security Audit — agent-trust-hub — mobile-ionic-capacitor