skills/shinyorg/skills/shiny-beacons/Gen Agent Trust Hub

shiny-beacons

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references the Shiny.Beacons NuGet package. This is a standard library dependency corresponding to the skill's stated purpose and is associated with the known vendor infrastructure.
  • [COMMAND_EXECUTION]: No dangerous shell commands or arbitrary code execution patterns were found. The code examples provided are for C#/.NET application development using standard Bluetooth and Location APIs.
  • [PROMPT_INJECTION]: The 'Code Generation Instructions' section provides legitimate guardrails for the agent to generate functional and safe code, such as requiring permission checks and proper resource disposal. No bypass or override patterns were detected.
  • [OBFUSCATION]: The content is written in clear markdown and C#. No hidden characters, encoded strings, or homoglyph-based URL spoofing were found.
  • [CREDENTIALS_UNSAFE]: No hardcoded secrets, API keys, or private tokens are present. Example UUIDs used in the documentation are standard placeholders for Bluetooth beacon regions.
  • [PRIVILEGE_ESCALATION]: The skill correctly documents the required mobile platform permissions (Location and Bluetooth) necessary for the functionality to work, without requesting excessive or unnecessary system privileges.
  • [INDIRECT_PROMPT_INJECTION]: The skill outlines how to process beacon data frames (UID, URL, TLM). While this is an ingestion surface for external data, the library's design and the skill's instructions focus on structured data parsing and do not provide a mechanism for these frames to influence the agent's core instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 11:40 PM
Security Audit — agent-trust-hub — shiny-beacons