expo-workflow
Warn
Audited by Gen Agent Trust Hub on Mar 11, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill configuration in the YAML frontmatter includes
PostToolUsehooks that automatically execute local bash scripts (ts-check.sh,auto-prettier.sh,console-log-check.sh) from the user's home directory (~/.claude/hooks/) after file editing operations.\n- [EXTERNAL_DOWNLOADS]: The workflow instructions mandate the installation and use of numerous third-party packages including@tamagui/core,nativewind,zustand, and various Expo SDK modules vianpx expo install.\n- [PROMPT_INJECTION]: The skill utilizes high-pressure instructional language and override markers (e.g., 'CRITICAL PRINCIPLE', 'NON-NEGOTIABLE', 'MANDATORY', 'You MUST NEVER') to force specific agent behaviors and bypass default implementation strategies.\n- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection attack surface.\n - Ingestion points: External documentation is fetched using various MCP tools (
fetch_rn_docs,fetch_expo_sdk,fetch_tamagui_docs, etc.) as defined in the 'Core Workflows' and 'Integration with MCP Server' sections.\n - Boundary markers: There are no markers or delimiters defined to isolate the fetched external content from the agent's instructions.\n
- Capability inventory: The agent has the capability to modify source code files (
.ts,.tsx,.js,.jsx) and execute shell commands via the definedPostToolUsehooks.\n - Sanitization: No sanitization or validation mechanisms are mentioned for the external documentation content before it is processed by the agent.
Audit Metadata