code-signing

Pass

Audited by Gen Agent Trust Hub on Aug 5, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides documentation and command guidance for managing iOS credentials using the official eas-cli tool, which is standard for Expo-based mobile development.
  • [SAFE]: The instructions include clear safety boundaries in the 'Credential and external action gate' section, explicitly forbidding the agent from creating, downloading, or revoking credentials without the owner's explicit confirmation.
  • [SAFE]: The skill promotes secure secret management by advising the use of eas secret:create and utilizing placeholders instead of hardcoding sensitive information like .p8 keys, Issuer IDs, or API keys directly in the code or prompts.
  • [SAFE]: Reference materials point to internal project guidelines and official documentation, maintaining a secure chain of information without introducing untrusted external scripts or remote code execution risks.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 5, 2026, 11:17 PM
Security Audit — agent-trust-hub — code-signing