mobile-app-builder-ios-android
Pass
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements a standard mobile development lifecycle including architecture planning, parity checks, and testing.
- [SAFE]: Explicitly mandates keeping sensitive credentials (Expo, Apple, Google, Firebase, etc.) out of source code and logs, which is a security best practice.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests user input for app requirements, creating a surface for indirect injection. However, the instructions are focused on development tasks and do not introduce unique vulnerabilities.
- [COMMAND_EXECUTION]: The skill utilizes standard Expo CLI commands (npx expo install) for dependency management, which is appropriate for its intended use case.
Audit Metadata