id-capture-android

Pass

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides legitimate developer documentation and code samples for the Scandit ID Capture Android SDK.
  • [PROMPT_INJECTION]: Evaluated instructions aimed at preventing API hallucinations and instructions regarding providing direct answers instead of deferring to external sites. These are interpreted as utility-enhancing prompt engineering rather than malicious concealment or safety bypass.
  • [DATA_EXFILTRATION]: All network references and dependencies originate from the vendor (scandit.com) or well-known software registries (sonatype.com). Sensitive credentials are appropriately represented by placeholders.
  • [REMOTE_CODE_EXECUTION]: No evidence of unauthorized remote script execution or dynamic code generation from untrusted sources.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines patterns for processing identity document data within an Android application. The surface is documented for development purposes and handles structured SDK output, representing minimal risk to the agent's operational logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 17, 2026, 03:17 AM
Security Audit — agent-trust-hub — id-capture-android