lov-mobile-adapt

Pass

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes content from untrusted external web projects as part of its scanning and fixing workflow. This creates a surface for indirect prompt injection if project files contain instructions designed to influence the agent's behavior during the modification phase.
  • Ingestion points: The scripts/scan_mobile_issues.py script reads the content of project files with various web-related extensions (e.g., .html, .css, .js, .tsx).
  • Boundary markers: The agent is instructed to use AskUserQuestion to collect scope and obtain user permission before making changes. It is also directed to use established implementation patterns from references/mobile-patterns.md rather than following arbitrary file instructions.
  • Capability inventory: The skill uses a Python script to read files and requires the agent to modify project source code based on scan results.
  • Sanitization: The scanner reads raw file content using standard library functions and does not implement specific filtering for prompt injection patterns before passing findings to the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 26, 2026, 03:51 PM
Security Audit — agent-trust-hub — lov-mobile-adapt