expo-api-routes

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides documentation and standard code snippets for building API routes in Expo Router, which is consistent with its stated purpose.
  • [SAFE]: It emphasizes security best practices, such as using server-side secrets via environment variables and ensuring sensitive credentials like OpenAI API keys are never exposed to the client.
  • [SAFE]: The skill references well-known and trusted developer tools, such as EAS CLI, and established cloud services like Cloudflare Workers and Supabase.
  • [INDIRECT_PROMPT_INJECTION]: The guide demonstrates how to handle external input via request bodies and parameters. While this is a standard feature for API routes, the documentation explicitly includes a rule to validate and sanitize all user input to mitigate injection risks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 11:19 PM
Security Audit — agent-trust-hub — expo-api-routes