expo-react-native-coder
Fail
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: HIGHCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The file
references/setup-environment-variables.mdcontains a hardcoded API key pattern (sk-) in an example demonstrating incorrect practices. - Evidence:
EXPO_PUBLIC_API_KEY=sk-secret-key-12345found in the 'Incorrect' code block. - [REMOTE_CODE_EXECUTION]: The file
references/test-e2e-maestro.mdinstructs the user to install a testing tool by piping a remote script directly into the shell. - Evidence:
curl -Ls "https://get.maestro.mobile.dev" | bashused for Maestro installation. - [INDIRECT_PROMPT_INJECTION]: The skill implements patterns for handling deep links and dynamic route segments that ingest untrusted data from URLs into the application context without explicit sanitization guidelines.
- Ingestion points:
useLocalSearchParamsis used inreferences/link-handle-incoming.mdandreferences/route-dynamic-segments.mdto capture data from external URLs. - Boundary markers: None identified in the provided examples for handling incoming link data.
- Capability inventory: The skill includes templates for network operations (
fetchinreferences/data-fetch-on-focus.md), local database access (expo-sqliteinreferences/data-sqlite-local.md), and secure storage (expo-secure-storeinreferences/data-secure-store.md). - Sanitization: There is no evidence of input validation or sanitization for parameters received through dynamic route segments before they are used in API calls or database queries.
Recommendations
- AI detected serious security threats
Audit Metadata