ns-ios-corespotlight

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides legitimate technical documentation for NativeScript developers to avoid V8 deadlocks in iOS apps. It recommends materializing JavaScript collections into native arrays and ensures completion handlers are dispatched to the main thread using the @nativescript/core utility library.
  • [DATA_EXPOSURE]: No hardcoded credentials, sensitive file paths, or unauthorized network exfiltration patterns were detected. The use of console.log for debugging and indexing status is standard practice.
  • [REMOTE_CODE_EXECUTION]: No remote script downloads or dangerous execution patterns (like piping curl to bash) are present. The skill utilizes standard NativeScript and iOS APIs.
  • [OBFUSCATION]: No obfuscation techniques, such as hidden Unicode characters, Base64-encoded commands, or homoglyphs, were found in the instructions or code snippets.
  • [INDIRECT_PROMPT_INJECTION]: The skill describes an architecture for processing application data and user activity for search indexing. While this involves ingesting external data (Category 8), the proposed implementation follows framework-standard deep-linking and indexing patterns without introducing exploitable agent logic. (Severity: Safe).
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 01:12 AM
Security Audit — agent-trust-hub — ns-ios-corespotlight