expo-deployment
Fail
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADS
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill instructs users to run
npx testflightfor iOS submissions across multiple files. Thetestflightpackage on the NPM registry is an unverified, deprecated third-party library not affiliated with Expo or Apple. Running unverified packages vianpxallows for the execution of arbitrary remote code.\n- [INDIRECT_PROMPT_INJECTION]: The skill provides instructions for automated metadata management that ingests external data. \n - Ingestion points: Processes data from
store.config.jsonand external API fetches instore.config.js(e.g., fetching from api.example.com).\n - Boundary markers: Lacks delimiters or safety instructions to prevent the agent from following commands embedded in the metadata.\n
- Capability inventory: Uses
eas metadata:pushandeas submitto transmit data to external production environments (App Stores).\n - Sanitization: No validation or sanitization is performed on the ingested content before it is pushed to production stores.\n- [COMMAND_EXECUTION]: The EAS Workflow examples use
type: runsteps to execute shell commands likegit diff. This job type provides a mechanism for arbitrary shell execution within the CI/CD environment.\n- [CREDENTIALS_UNSAFE]: Sample configuration files include hardcoded credentials (demoPassword) in the metadata review section. Hardcoding passwords in configuration files is a security risk if these files are committed to version control or shared.\n- [EXTERNAL_DOWNLOADS]: The skill usesnpm install -g eas-cliandnpx testflight, which download packages from the public NPM registry. Whileeas-cliis a well-known tool,testflightis an unverified external dependency.
Recommendations
- AI detected serious security threats
Audit Metadata