label-capture-web

Pass

Audited by Gen Agent Trust Hub on May 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a legitimate developer aid for the Scandit Label Capture SDK, providing accurate technical documentation and code generation patterns based on official references.
  • [EXTERNAL_DOWNLOADS]: The skill references official Scandit documentation (docs.scandit.com), GitHub repositories (github.com/Scandit), and uses well-known CDNs (cdn.jsdelivr.net) for library delivery. These are verified vendor resources and well-known services.
  • [DATA_EXFILTRATION]: No credential harvesting or sensitive data access patterns were identified. The skill correctly instructs users to use placeholders for license keys.
  • [PROMPT_INJECTION]: The skill uses instructional grounding (e.g., "Do Not Trust Internal Knowledge") to improve the accuracy of the LLM's responses based on the provided technical references. Static analysis flags regarding concealment are false positives, as they refer to specific UI layout requirements (full-screen Validation Flow) and standard documentation-fetching behaviors.
  • [COMMAND_EXECUTION]: The skill does not execute dangerous shell commands or attempt privilege escalation. It provides standard installation instructions for npm/yarn packages.
Audit Metadata
Risk Level
SAFE
Analyzed
May 18, 2026, 01:15 PM
Security Audit — agent-trust-hub — label-capture-web