Push Notification Wirer
Pass
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [NO_CODE]: The skill consists entirely of markdown documentation and instructions. It does not include any scripts, executable files, or automated command-line operations that could be exploited.
- [SAFE]: No malicious patterns, such as prompt injection or obfuscation, were identified. The skill provides defensive security advice, such as warning against the blind execution of URLs found in push payloads and recommending proper token lifecycle management.
- [CREDENTIALS_UNSAFE]: The documentation discusses the use of authentication artifacts like Apple .p8 keys and Google service accounts. However, it does not provide or hardcode any actual secrets; it only describes their role in the push notification infrastructure.
- [DATA_EXFILTRATION]: The skill describes the transmission of device tokens to a developer-controlled server. This is a documented and standard requirement for functioning push notification systems and does not represent an unauthorized exfiltration of sensitive user data.
Audit Metadata