matrixscan-ar-annotation-ios

Pass

Audited by Gen Agent Trust Hub on May 12, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a specialized development tool for the Scandit iOS SDK. It provides structured guidance and official documentation links for implementing augmented reality barcode annotations.
  • [PROMPT_INJECTION]: Static detectors flagged potential concealment of actions in the skill's instructions. Upon review, these instructions (e.g., "Do not tell the user to check the docs themselves") are UX guidelines intended to ensure the agent provides direct answers rather than offloading the task to the user. This is not a malicious attempt to bypass safety or hide malicious behavior.
  • [EXTERNAL_DOWNLOADS]: All external references point to official Scandit documentation (docs.scandit.com) or the official Scandit GitHub repository. These sources are owned by the vendor and are appropriate for the skill's stated purpose.
  • [CREDENTIALS_UNSAFE]: The included code fixtures for UIKit and SwiftUI correctly use placeholders such as '-- ENTER YOUR SCANDIT LICENSE KEY HERE --' for sensitive information, demonstrating proper secret management practices.
  • [DATA_EXPOSURE]: No patterns for unauthorized sensitive file access or data exfiltration to non-vendor domains were found.
  • [SAFE]: The skill identifies user project content (e.g., searching for BarcodeArView) to provide contextual advice. While this represents a data ingestion surface, it is a necessary functional requirement for a coding assistant and is not combined with dangerous capabilities such as arbitrary command execution or network exfiltration.
Audit Metadata
Risk Level
SAFE
Analyzed
May 12, 2026, 07:16 AM
Security Audit — agent-trust-hub — matrixscan-ar-annotation-ios