mobile-design

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists of extensive documentation teaching best practices for mobile design and development, focusing on performance, accessibility, and security. No malicious instructions or hidden payloads were detected.
  • [DATA_EXFILTRATION]: No evidence of data exfiltration, credential harvesting, or unauthorized network operations was found. The skill explicitly guides the agent to use secure storage (iOS Keychain / Android EncryptedSharedPreferences) for sensitive tokens and warns against hardcoding secrets.
  • [REMOTE_CODE_EXECUTION]: The skill includes a local utility script scripts/mobile_audit.py. This script performs static regex-based analysis on code within the current workspace to check for performance and touch-target issues. It includes a safe_user_path function that explicitly prevents directory traversal by ensuring all analyzed paths are relative to the current working directory.
  • [PROMPT_INJECTION]: The skill uses strong language to enforce design principles (e.g., '🔴 REQUIRED FIRST', 'Non-Negotiable', 'Hard Bans'). These instructions are intended to scope the AI agent's creative process toward professional mobile development standards and do not attempt to bypass underlying model safety constraints or exfiltrate system prompts.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 02:43 PM
Security Audit — agent-trust-hub — mobile-design