native-data-fetching

Pass

Audited by Gen Agent Trust Hub on Jul 14, 2026

Risk Level: SAFE
Full Analysis
  • [CREDENTIALS_UNSAFE]: No hardcoded credentials or secrets were found. The skill correctly demonstrates how to handle authentication tokens using expo-secure-store and how to access server-side secrets using non-prefixed environment variables in Expo Router loaders.
  • [DATA_EXFILTRATION]: No patterns of unauthorized data exfiltration were detected. Network operations shown in examples target generic placeholders like api.example.com or well-known services like Stripe for demonstration purposes.
  • [PROMPT_INJECTION]: The skill contains standard instructional content and documentation. There are no attempts to override agent behavior or bypass safety filters.
  • [INDIRECT_PROMPT_INJECTION]: The skill identifies ingestion points for external data via API fetches. It addresses security by explicitly recommending that developers validate and sanitize user input (params and query strings) before using them in database queries or API calls, mitigating common injection risks.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 14, 2026, 10:58 AM
Security Audit — agent-trust-hub — native-data-fetching