matrixscan-ar-highlight-ios
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill contains grounding instructions labeled 'Critical: Do Not Trust Internal Knowledge' and 'API Usage Policy'. These are standard technical constraints designed to prevent the AI agent from hallucinating or providing outdated SDK method signatures. They do not attempt to bypass safety filters, redefine the agent's core safety mission, or extract system prompts.
- [EXTERNAL_DOWNLOADS]: The skill references official Scandit documentation at
docs.scandit.comand sample code on GitHub atgithub.com/Scandit/datacapture-ios-samples. These resources originate from the verified vendor and are used purely for referencing API signatures and implementation patterns. - [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to search the user's project for existing SDK usage (e.g.,
BarcodeArView). While this involves ingesting untrusted local data, the skill's capabilities are limited to providing coding suggestions and documentation. It lacks dangerous automated execution capabilities that would escalate this surface to a high-risk finding.
Audit Metadata