id-capture-capacitor
Pass
Audited by Gen Agent Trust Hub on Jul 17, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill uses imperative instructions (e.g., 'Critical: Do Not Trust Internal Knowledge', 'Forbidden APIs') to override the agent's base training data. These instructions are evaluated as benign and necessary to ensure technical accuracy due to significant API changes between SDK versions (v6, v7, and v8).
- [INDIRECT_PROMPT_INJECTION]: The skill describes how to handle data ingested from identity documents via a scanner (e.g., MRZ, barcodes). While this presents a potential surface for indirect prompt injection if the agent were to process document content directly, the skill's primary purpose is generating application code. The provided templates focus on UI rendering and standard lifecycle management without exposing the agent to untrusted data processing.
- [CREDENTIALS_UNSAFE]: The skill correctly uses placeholders like '-- ENTER YOUR SCANDIT LICENSE KEY HERE --' for sensitive information and instructs users to configure license keys rather than hardcoding them, aligning with security best practices.
- [EXTERNAL_DOWNLOADS]: All external references and documentation links point to official vendor resources (scandit.com and github.com/Scandit), which are verified as safe originating from the skill's author.
Audit Metadata