upgrade-react-native

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection via the consumption of external documentation.
  • Ingestion points: In step 7 of SKILL.md, the skill fetches third-party library README files from external GitHub repositories or npm pages to check for version compatibility.
  • Boundary markers: No specific boundary markers or isolation instructions are provided to prevent the agent from obeying instructions embedded inside those external README files.
  • Capability inventory: The skill has the capability to write and modify local project files, including package.json, native Android/iOS files, and configuration files.
  • Sanitization: There is no automated validation or sanitization applied to the retrieved README content before it is parsed by the model.
  • [EXTERNAL_DOWNLOADS]: The skill downloads release metadata and unified diff files from the react-native-community/rn-diff-purge repository and alternative platform diffs from acoates-ms/rnw-diff to identify and apply required codebase changes.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 10:14 AM