command-ship-it

Pass

Audited by Gen Agent Trust Hub on Aug 5, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill follows security best practices by requiring explicit human confirmation before executing any sensitive external actions, such as generating builds, uploading binaries, or submitting to app stores.
  • [PROMPT_INJECTION]: The skill ingests Expo project context to automate deployment tasks, which presents an indirect prompt injection surface. 1. Ingestion points: Expo project files and coding-agent host context. 2. Boundary markers: Not explicitly defined within the instructions. 3. Capability inventory: Preparation and potential execution of EAS CLI commands for build and submission. 4. Sanitization: Risk is mitigated by mandatory human-in-the-loop validation steps defined in the workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 5, 2026, 11:17 PM
Security Audit — agent-trust-hub — command-ship-it