hz-react-native-expo

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to use standard development tools such as npx, npm, yarn, expo, and metavr to manage dependencies, build applications, and interact with devices via ADB. These operations are core to the skill's functionality as a development tool.
  • [EXTERNAL_DOWNLOADS]: The skill references several external resources, including official NPM packages like expo-horizon-core and expo-dev-client, as well as the Meta Horizon Store for Expo Go. These downloads originate from well-known and trusted services, which align with the skill's stated purpose and do not pose a security risk.
  • [INDIRECT_PROMPT_INJECTION]: The skill operates on user-provided application code and project configuration files. While this represents a potential attack surface for indirect prompt injection, the skill's primary focus is on building and running the code on external hardware, and it does not contain logic that would lead to the execution of untrusted instructions within the agent's reasoning process.
  • [SAFE]: No malicious patterns, obfuscation, or unauthorized data access were detected. The skill follows best practices for development tooling, such as using environment-level dependency management and referencing official documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 06:28 PM
Security Audit — agent-trust-hub — hz-react-native-expo