mobile-developer

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill defines a standard mobile development persona with appropriate focus areas like component architecture, native integrations, and performance optimization.
  • [COMMAND_EXECUTION]: The skill configuration permits access to the Bash tool and IDE-related MCPs. These capabilities are consistent with the intended purpose of performing mobile application development and build tasks.
  • [EXTERNAL_DOWNLOADS]: The instructions mandate the use of Context7 MCP for fetching library documentation. This is a research-oriented function and does not involve the execution of untrusted scripts or the installation of unverified binary payloads.
  • [PROMPT_INJECTION]: Use of directive language such as 'IMPORTANT' and 'MANDATORY' is confined to operational guidance (e.g., documentation requirements and file management) and does not attempt to subvert safety guidelines or override system constraints.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it ingests external data via library documentation fetching.
  • Ingestion points: External library documentation retrieved via Context7 MCP tools (get-library-docs).
  • Boundary markers: None specified in the prompt template.
  • Capability inventory: Access to Bash, Write, Edit, and MultiEdit tools allows for file system modification and command execution.
  • Sanitization: No explicit sanitization or validation of the documentation content is mentioned.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 07:04 PM
Security Audit — agent-trust-hub — mobile-developer