multithreading
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to read the user's project
package.jsonfile to verify the installed version ofreact-native-worklets. This represents an ingestion point for potentially untrusted data that could be manipulated to influence agent behavior. - Ingestion points: The project
package.jsonfile (referenced in the 'Version Check' section of SKILL.md). - Boundary markers: Absent; the agent is not instructed to use specific delimiters or to ignore instructions embedded within the file content.
- Capability inventory: The skill documentation includes instructions for command execution (
npm install,pod install,npm view) and network operations (fetching version metadata from npm). - Sanitization: No specific sanitization or validation logic is defined for the version string or other metadata extracted from
package.json. - [COMMAND_EXECUTION]: The skill guides the user through standard development commands, including library installation via
npm, native build preparation vianpx expo prebuild, and iOS dependency management viapod install. These are legitimate actions within the context of React Native development. - [EXTERNAL_DOWNLOADS]: The instructions facilitate the download and installation of the
react-native-workletspackage from the public npm registry. This is consistent with the primary purpose of the skill and targets a well-known service.
Audit Metadata