expo-react-native-expert
Pass
Audited by Gen Agent Trust Hub on Jun 15, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The instructions do not contain any patterns attempting to override agent behavior, bypass safety guidelines, or extract system prompts. The guidance is strictly focused on technical mobile development standards.
- [DATA_EXFILTRATION]: No network operations, sensitive file path access, or credential patterns were detected. The skill mentions 'SecureStore' as a best practice for mobile storage, which is a standard security recommendation in the React Native ecosystem.
- [COMMAND_EXECUTION]: The skill does not contain any shell commands, subprocess calls, or scripts. It explicitly instructs against 'unsafe ejection' from the Expo managed workflow, promoting a more secure development environment.
- [REMOTE_CODE_EXECUTION]: There are no external downloads or remote script executions. While it mentions specific libraries like 'FlashList' and 'Reanimated 3', it does not attempt to install them or execute untrusted code.
- [OBFUSCATION]: The file contains clear, human-readable text with no Base64, zero-width characters, or other hidden encoding techniques.
- [PRIVILEGE_ESCALATION]: No privilege escalation patterns, such as sudo or permissions modifications, are present.
- [METADATA_POISONING]: The metadata is consistent with the skill's description and purpose. Although it references a non-existent model version ('gpt-5.4'), this appears to be a placeholder or a misconfiguration by the author rather than a malicious deception.
Audit Metadata