mobile-app-interface
Warn
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONMETADATA_POISONING
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides instructions to install unverified Node.js packages
expo-glass-effectandexpo-liquid-glass-view. These are not standard Expo modules and do not follow the author's vendor naming conventions, posing a risk of dependency confusion or supply chain attacks. - [COMMAND_EXECUTION]: The skill explicitly commands the agent or user to execute
npx expo installfor the aforementioned unverified packages, which could lead to the execution of arbitrary code if those packages are malicious. - [METADATA_POISONING]: The skill references fictitious technology versions, such as "iOS 26" and "Liquid Glass" native support. This deceptive or hallucinated technical context could mislead users into applying incorrect security configurations or installing unsafe third-party components.
Audit Metadata