expo-workflow

Warn

Audited by Gen Agent Trust Hub on Mar 11, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill configuration in the YAML frontmatter includes PostToolUse hooks that automatically execute local bash scripts (ts-check.sh, auto-prettier.sh, console-log-check.sh) from the user's home directory (~/.claude/hooks/) after file editing operations.\n- [EXTERNAL_DOWNLOADS]: The workflow instructions mandate the installation and use of numerous third-party packages including @tamagui/core, nativewind, zustand, and various Expo SDK modules via npx expo install.\n- [PROMPT_INJECTION]: The skill utilizes high-pressure instructional language and override markers (e.g., 'CRITICAL PRINCIPLE', 'NON-NEGOTIABLE', 'MANDATORY', 'You MUST NEVER') to force specific agent behaviors and bypass default implementation strategies.\n- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection attack surface.\n
  • Ingestion points: External documentation is fetched using various MCP tools (fetch_rn_docs, fetch_expo_sdk, fetch_tamagui_docs, etc.) as defined in the 'Core Workflows' and 'Integration with MCP Server' sections.\n
  • Boundary markers: There are no markers or delimiters defined to isolate the fetched external content from the agent's instructions.\n
  • Capability inventory: The agent has the capability to modify source code files (.ts, .tsx, .js, .jsx) and execute shell commands via the defined PostToolUse hooks.\n
  • Sanitization: No sanitization or validation mechanisms are mentioned for the external documentation content before it is processed by the agent.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 11, 2026, 02:13 AM