multithreading

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to read the user's project package.json file to verify the installed version of react-native-worklets. This represents an ingestion point for potentially untrusted data that could be manipulated to influence agent behavior.
  • Ingestion points: The project package.json file (referenced in the 'Version Check' section of SKILL.md).
  • Boundary markers: Absent; the agent is not instructed to use specific delimiters or to ignore instructions embedded within the file content.
  • Capability inventory: The skill documentation includes instructions for command execution (npm install, pod install, npm view) and network operations (fetching version metadata from npm).
  • Sanitization: No specific sanitization or validation logic is defined for the version string or other metadata extracted from package.json.
  • [COMMAND_EXECUTION]: The skill guides the user through standard development commands, including library installation via npm, native build preparation via npx expo prebuild, and iOS dependency management via pod install. These are legitimate actions within the context of React Native development.
  • [EXTERNAL_DOWNLOADS]: The instructions facilitate the download and installation of the react-native-worklets package from the public npm registry. This is consistent with the primary purpose of the skill and targets a well-known service.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 03:24 PM
Security Audit — agent-trust-hub — multithreading