shiny-firestore-mobile
Pass
Audited by Gen Agent Trust Hub on Aug 28, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill functions as a developer guide for a specific .NET mobile library. It contains legitimate configuration examples and architectural constraints expected for mobile database integration.
- [PROMPT_INJECTION]: The documentation contains instructions for the AI agent to follow when generating code (e.g., 'Code generation rules'). A static hint regarding concealment was evaluated and found to be a technical disclosure requirement (instructing the agent to be transparent about the lack of native auth integration) rather than an attempt to hide malicious behavior.
- [CREDENTIALS_UNSAFE]: No hardcoded secrets or credentials were found. The skill explicitly warns users against embedding service account keys in shipped mobile applications, which is a security best practice.
- [EXTERNAL_DOWNLOADS]: The skill references a legitimate NuGet package (Shiny.DocumentDb.Firestore.Mobile) from the vendor's ecosystem. No suspicious or unverified third-party scripts are downloaded or executed.
- [DATA_EXFILTRATION]: No patterns of sensitive file access or unauthorized network data transmission were identified.
Audit Metadata