command-ship-it
Pass
Audited by Gen Agent Trust Hub on Aug 5, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill follows security best practices by requiring explicit human confirmation before executing any sensitive external actions, such as generating builds, uploading binaries, or submitting to app stores.
- [PROMPT_INJECTION]: The skill ingests Expo project context to automate deployment tasks, which presents an indirect prompt injection surface. 1. Ingestion points: Expo project files and coding-agent host context. 2. Boundary markers: Not explicitly defined within the instructions. 3. Capability inventory: Preparation and potential execution of EAS CLI commands for build and submission. 4. Sanitization: Risk is mitigated by mandatory human-in-the-loop validation steps defined in the workflow.
Audit Metadata