skills/scandit/skills/sparkscan-rn/Gen Agent Trust Hub

sparkscan-rn

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill contains instructions that steer the agent's interaction style, such as 'Do not just show the code in chat; apply it to the file' and 'Do not tell the user to check the docs themselves'. While these patterns are identified as interaction concealment, in the context of a developer tool, they represent standard operational instructions for an AI coding agent to perform task automation and reduce conversational noise rather than attempts to hide malicious activity.
  • [SAFE]: All referenced documentation links (docs.scandit.com, ssl.scandit.com) and source code repositories (github.com/Scandit) are official Scandit vendor resources. The required Node.js packages (scandit-react-native-datacapture-core, scandit-react-native-datacapture-barcode) are the standard SDK components provided by the vendor. The instructions follow standard React Native best practices for native linking and permission handling.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 04:33 PM
Security Audit — agent-trust-hub — sparkscan-rn