expo-cicd-workflows
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches JSON schemas and syntax documentation from official Expo domains (
api.expo.dev) and their public GitHub repository (github.com/expo/expo). - [COMMAND_EXECUTION]: Executes local Node.js utility scripts (
fetch.jsandvalidate.js) to process documentation and perform file validation, which involves installing standard dependencies from the npm registry. - [INDIRECT_PROMPT_INJECTION]: The skill processes project-level workflow files, which is a standard surface for indirect prompt injection.
- Ingestion points: The
validate.jsscript reads YAML files located in.eas/workflows/. - Boundary markers: No specific delimiters or instructions to ignore embedded commands were identified in the script logic.
- Capability inventory: The skill has capabilities for network fetching, local file reading, and writing to a local cache directory.
- Sanitization: The tool uses
js-yaml.load(), which is the safe version of the YAML parser and prevents code execution during deserialization.
Audit Metadata