expo-api-routes
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides documentation and standard code snippets for building API routes in Expo Router, which is consistent with its stated purpose.
- [SAFE]: It emphasizes security best practices, such as using server-side secrets via environment variables and ensuring sensitive credentials like OpenAI API keys are never exposed to the client.
- [SAFE]: The skill references well-known and trusted developer tools, such as EAS CLI, and established cloud services like Cloudflare Workers and Supabase.
- [INDIRECT_PROMPT_INJECTION]: The guide demonstrates how to handle external input via request bodies and parameters. While this is a standard feature for API routes, the documentation explicitly includes a rule to validate and sanitize all user input to mitigate injection risks.
Audit Metadata