sparkscan-rn
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill contains instructions that steer the agent's interaction style, such as 'Do not just show the code in chat; apply it to the file' and 'Do not tell the user to check the docs themselves'. While these patterns are identified as interaction concealment, in the context of a developer tool, they represent standard operational instructions for an AI coding agent to perform task automation and reduce conversational noise rather than attempts to hide malicious activity.
- [SAFE]: All referenced documentation links (docs.scandit.com, ssl.scandit.com) and source code repositories (github.com/Scandit) are official Scandit vendor resources. The required Node.js packages (scandit-react-native-datacapture-core, scandit-react-native-datacapture-barcode) are the standard SDK components provided by the vendor. The instructions follow standard React Native best practices for native linking and permission handling.
Audit Metadata