sparkscan-android
Pass
Audited by Gen Agent Trust Hub on May 12, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill retrieves documentation from 'docs.scandit.com' and checks version metadata on Maven Central ('central.sonatype.com'). These actions involve data retrieval from trusted and well-known domains essential for accurate SDK integration and do not involve execution of untrusted scripts.
- [PROMPT_INJECTION]: A static detection for instruction concealment was identified as a false positive. The instruction 'Do not tell the user to check the docs themselves' is designed to improve agent helpfulness by providing direct answers and is accompanied by a requirement to provide official reference links for verification.
- [COMMAND_EXECUTION]: The skill manages Kotlin source code modifications within the provided Android project files for SDK setup. It does not perform unauthorized shell command execution, privilege escalation, or persistence attempts on the host system.
- [SAFE]: Overall, the skill is correctly scoped to its declared purpose of assisting with Scandit SDK integration and demonstrates safe handling of external references and user code. No malicious patterns or security risks were identified.
Audit Metadata