matrixscan-ar-web
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as a technical reference for integrating the Scandit MatrixScan AR SDK into web applications. All external resources, including documentation, code samples, and library downloads, originate from official vendor domains (scandit.com) or trusted public repositories (github.com/Scandit).
- [EXTERNAL_DOWNLOADS]: The instructions reference official Scandit NPM packages (@scandit/web-datacapture-core, @scandit/web-datacapture-barcode) and suggest using the Scandit CDN (cdn.jsdelivr.net) for hosting SDK engine files. These are standard practices for web SDK integration and target verified vendor resources.
- [PROMPT_INJECTION]: The skill contains instructions for the AI to prioritize the provided reference material over its internal training data to avoid cross-platform API confusion (e.g., between Web and React Native). These instructions are aimed at improving technical accuracy and do not attempt to bypass safety filters or exfiltrate data.
- [INDIRECT_PROMPT_INJECTION]: The skill handles data scanned from barcodes (barcode.data) for display in AR annotations. While this is an entry point for untrusted data, the skill's logic is restricted to rendering UI elements (highlights and text labels) and does not involve executing the data or using it in sensitive operations.
Audit Metadata