lov-mobile-adapt
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes content from untrusted external web projects as part of its scanning and fixing workflow. This creates a surface for indirect prompt injection if project files contain instructions designed to influence the agent's behavior during the modification phase.
- Ingestion points: The
scripts/scan_mobile_issues.pyscript reads the content of project files with various web-related extensions (e.g., .html, .css, .js, .tsx). - Boundary markers: The agent is instructed to use
AskUserQuestionto collect scope and obtain user permission before making changes. It is also directed to use established implementation patterns fromreferences/mobile-patterns.mdrather than following arbitrary file instructions. - Capability inventory: The skill uses a Python script to read files and requires the agent to modify project source code based on scan results.
- Sanitization: The scanner reads raw file content using standard library functions and does not implement specific filtering for prompt injection patterns before passing findings to the agent.
Audit Metadata