matrixscan-ar-ios

Pass

Audited by Gen Agent Trust Hub on May 12, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The overall logic and instructions of the skill are aligned with its stated purpose of assisting with Scandit SDK integration. No malicious or deceptive patterns were identified.
  • [PROMPT_INJECTION]: Instructions directing the agent to 'apply code directly to the file' and 'not tell the user to check the docs themselves' were evaluated. These are behavioral guidelines intended to enhance the agent's utility for the developer (by performing edits and providing links) and do not constitute malicious concealment or jailbreak attempts.
  • [EXTERNAL_DOWNLOADS]: The skill points to official Scandit repositories on GitHub for package management (SPM) and official Scandit documentation. These domains (github.com and scandit.com) are legitimate and belong to the vendor of the SDK.
  • [CREDENTIALS_UNSAFE]: Sample code and integration instructions use a standard placeholder ('-- ENTER YOUR SCANDIT LICENSE KEY HERE --') for license keys, which is a secure and standard practice for documentation and sample projects.
  • [DATA_EXFILTRATION]: No patterns indicative of data exfiltration or unauthorized sensitive file access were found. The network operations are limited to fetching documentation and installing standard libraries.
Audit Metadata
Risk Level
SAFE
Analyzed
May 12, 2026, 07:16 AM