app-store-review
Pass
Audited by Gen Agent Trust Hub on Aug 30, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: The skill consists entirely of markdown guidelines, checklists, and code snippets intended to assist an AI agent in auditing application code for App Store compliance. No executable scripts or dangerous instructions were found.
- [NO_CODE]: The skill package contains no executable logic (such as shell scripts, Python, or JavaScript files). It relies solely on natural language instructions and documentation to guide the agent's behavior during a code audit.
- [INDIRECT_PROMPT_INJECTION]: While the skill is designed to process untrusted application code (an ingestion point for potential indirect prompt injection), it possesses no tool-based capabilities (such as network access, file system writes, or subprocess execution) that could be exploited. The risk is localized to the agent's output interpretation rather than system-level safety.
- [CREDENTIALS_SAFE]: The documentation includes code snippets with placeholder secrets (e.g., 'sk_live_xxxxx') used specifically to illustrate patterns that the agent should flag as security risks. These are not functional credentials.
- [EXTERNAL_DOWNLOADS]: All referenced URLs point to official Apple developer resources, well-known development tools, or the vendor's own verified repository. No suspicious or unverified third-party sources were identified.
Audit Metadata