label-capture-capacitor

Pass

Audited by Gen Agent Trust Hub on May 18, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill contains instructions to prioritize the provided documentation over training data and specifies API usage policies. These are benign instructions designed to ensure technical accuracy and do not attempt to bypass safety filters or extract system prompts. Static detection of 'concealment' is a false positive related to technical documentation regarding Capacitor's UI layering (webViewContentOnTop toggle), which is necessary for the SDK to function correctly.
  • [EXTERNAL_DOWNLOADS]: The skill references official documentation and sample code from Scandit's verified domains (docs.scandit.com) and GitHub repositories (github.com/Scandit). These are trusted vendor resources.
  • [DATA_EXFILTRATION]: No evidence of unauthorized data access or exfiltration. The skill uses standard placeholders for license keys and logs scan results locally for demonstration purposes as part of its primary scanning function.
  • [COMMAND_EXECUTION]: The skill mentions standard development commands such as 'npx cap sync' and 'pod install', which are routine for Capacitor and iOS development. No malicious command execution patterns or privilege escalation attempts were found.
  • [SAFE]: The skill follows security best practices by recommending the use of environment variables or placeholders for secrets rather than hardcoding credentials.
Audit Metadata
Risk Level
SAFE
Analyzed
May 18, 2026, 01:15 PM
Security Audit — agent-trust-hub — label-capture-capacitor