matrixscan-count-android

Pass

Audited by Gen Agent Trust Hub on Aug 1, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides documentation and implementation guides for the Scandit MatrixScan Count Android SDK. No malicious code or scripts are included within the skill files.
  • [SAFE]: All external references target official Scandit domains or the official Scandit GitHub organization, which is consistent with the skill's author ('scandit').
  • [SAFE]: Instructions for handling sensitive data, such as license keys, correctly use safe placeholders (e.g., '-- ENTER YOUR SCANDIT LICENSE KEY HERE --') and direct users to the official vendor dashboard for credential management.
  • [SAFE]: The skill correctly instructs the agent to fetch the latest SDK versions from Maven Central, a well-known and established repository for Android dependencies.
  • [SAFE]: A static detector flagged a potential concealment pattern; however, review of the instructions confirms this refers to an instructional preference ('Do not tell the user to check the docs themselves') aimed at ensuring the agent provides direct assistance rather than redirecting the user, which is a benign quality-of-service instruction.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines workflows for processing data from scanned barcodes via the TrackedBarcode object. This represents an ingestion point for untrusted external data. While no unsafe interpolation or exfiltration logic is present in the documentation, it is noted as a standard architectural risk surface for LLM-integrated barcode scanning applications.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 1, 2026, 10:30 AM
Security Audit — agent-trust-hub — matrixscan-count-android