ns-ios-corespotlight
Pass
Audited by Gen Agent Trust Hub on Aug 28, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides legitimate technical documentation for NativeScript developers to avoid V8 deadlocks in iOS apps. It recommends materializing JavaScript collections into native arrays and ensures completion handlers are dispatched to the main thread using the
@nativescript/coreutility library. - [DATA_EXPOSURE]: No hardcoded credentials, sensitive file paths, or unauthorized network exfiltration patterns were detected. The use of
console.logfor debugging and indexing status is standard practice. - [REMOTE_CODE_EXECUTION]: No remote script downloads or dangerous execution patterns (like piping curl to bash) are present. The skill utilizes standard NativeScript and iOS APIs.
- [OBFUSCATION]: No obfuscation techniques, such as hidden Unicode characters, Base64-encoded commands, or homoglyphs, were found in the instructions or code snippets.
- [INDIRECT_PROMPT_INJECTION]: The skill describes an architecture for processing application data and user activity for search indexing. While this involves ingesting external data (Category 8), the proposed implementation follows framework-standard deep-linking and indexing patterns without introducing exploitable agent logic. (Severity: Safe).
Audit Metadata