expo-react-native-coder

Fail

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: HIGHCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The file references/setup-environment-variables.md contains a hardcoded API key pattern (sk-) in an example demonstrating incorrect practices.
  • Evidence: EXPO_PUBLIC_API_KEY=sk-secret-key-12345 found in the 'Incorrect' code block.
  • [REMOTE_CODE_EXECUTION]: The file references/test-e2e-maestro.md instructs the user to install a testing tool by piping a remote script directly into the shell.
  • Evidence: curl -Ls "https://get.maestro.mobile.dev" | bash used for Maestro installation.
  • [INDIRECT_PROMPT_INJECTION]: The skill implements patterns for handling deep links and dynamic route segments that ingest untrusted data from URLs into the application context without explicit sanitization guidelines.
  • Ingestion points: useLocalSearchParams is used in references/link-handle-incoming.md and references/route-dynamic-segments.md to capture data from external URLs.
  • Boundary markers: None identified in the provided examples for handling incoming link data.
  • Capability inventory: The skill includes templates for network operations (fetch in references/data-fetch-on-focus.md), local database access (expo-sqlite in references/data-sqlite-local.md), and secure storage (expo-secure-store in references/data-secure-store.md).
  • Sanitization: There is no evidence of input validation or sanitization for parameters received through dynamic route segments before they are used in API calls or database queries.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 15, 2026, 10:17 AM
Security Audit — agent-trust-hub — expo-react-native-coder