skills/scandit/skills/sparkscan-ios/Gen Agent Trust Hub

sparkscan-ios

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides standard documentation and integration guides for the Scandit SparkScan SDK. All external links point to the vendor's official documentation (docs.scandit.com), licensing portal (ssl.scandit.com), or official GitHub repositories.
  • [SAFE]: Instructions for the agent to modify code and manage dependencies (SPM, CocoaPods) are standard for a development-focused skill and do not involve unauthorized privilege escalation or persistence.
  • [INDIRECT_PROMPT_INJECTION]: The skill involves reading and modifying user project files (source code, dependency manifests). While this presents a surface for indirect prompt injection if user files contained malicious instructions, it is an inherent part of the skill's primary function and is treated as low risk given the specific context of SDK integration.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 04:33 PM
Security Audit — agent-trust-hub — sparkscan-ios