matrixscan-ar-highlight-ios

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill contains grounding instructions labeled 'Critical: Do Not Trust Internal Knowledge' and 'API Usage Policy'. These are standard technical constraints designed to prevent the AI agent from hallucinating or providing outdated SDK method signatures. They do not attempt to bypass safety filters, redefine the agent's core safety mission, or extract system prompts.
  • [EXTERNAL_DOWNLOADS]: The skill references official Scandit documentation at docs.scandit.com and sample code on GitHub at github.com/Scandit/datacapture-ios-samples. These resources originate from the verified vendor and are used purely for referencing API signatures and implementation patterns.
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to search the user's project for existing SDK usage (e.g., BarcodeArView). While this involves ingesting untrusted local data, the skill's capabilities are limited to providing coding suggestions and documentation. It lacks dangerous automated execution capabilities that would escalate this surface to a high-risk finding.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 04:32 PM
Security Audit — agent-trust-hub — matrixscan-ar-highlight-ios