matrixscan-batch-ios
Pass
Audited by Gen Agent Trust Hub on Jun 29, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill contains strong instructions to prioritize provided reference materials over training data (e.g., 'Do Not Trust Internal Knowledge'). These are legitimate steering instructions to ensure API accuracy and do not attempt to bypass safety filters or conceal malicious behavior.
- [INDIRECT_PROMPT_INJECTION]: The skill operates by reading and transforming user-provided source code (UIKit/SwiftUI files and dependency manifests). While this presents an attack surface where malicious code in a project could attempt to influence the agent's behavior, the skill contains no exploitable capabilities within the agent environment that would escalate this beyond a standard operational risk.
- [EXTERNAL_DOWNLOADS]: The skill references and directs the agent to fetch documentation from 'docs.scandit.com' and recommends dependencies from the official Scandit GitHub repository ('github.com/Scandit/datacapture-spm'). These are recognized as legitimate vendor resources and do not represent a security risk.
- [CREDENTIALS_UNSAFE]: The instructions and examples use placeholders like '-- ENTER YOUR SCANDIT LICENSE KEY HERE --' for SDK authentication. No hardcoded secrets or sensitive credentials were found in the skill content.
Audit Metadata