app-store-keyword-ops

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external, third-party sources (App Store listings and Astro competitor metrics) to generate content that is eventually written to a live production environment (App Store Connect).
  • Ingestion points: Data enters the context from the app-store-scraper and aso tools in Step 2, and competitor metrics from the Astro MCP in Step 3.
  • Boundary markers: The skill lacks explicit instructions to treat these external strings as untrusted data or to use delimiters to prevent the agent from following instructions potentially hidden in app titles or descriptions.
  • Capability inventory: The skill has the capability to write to the App Store via helm-asc as described in Step 6.
  • Sanitization: No sanitization or escaping of the ingested text is performed before it is used to compose new keyword strings or presented to the user.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 09:07 AM
Security Audit — agent-trust-hub — app-store-keyword-ops