sota-mobile
Pass
Audited by Gen Agent Trust Hub on Aug 5, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill contains no evidence of malicious code, obfuscation, or unauthorized data access. It promotes industry-standard security models like OWASP MASVS and hardware-backed credential management.
- [PROMPT_INJECTION]: As an auditing tool, the skill involves the agent processing untrusted mobile source code, which represents a surface for indirect prompt injection.
- Ingestion points: User-provided mobile application source code and configuration files.
- Boundary markers: No explicit instructions for the agent to use delimiters or ignore embedded instructions when reading code are provided.
- Capability inventory: The skill guides agent reasoning; security is maintained by the host agent's restricted tool environment.
- Sanitization: No sanitization of input source code is explicitly mandated.
Audit Metadata