pulsar-haptics

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from project manifest files and external documentation.
  • Ingestion points: Manifest files (package.json, build.gradle, pubspec.yaml) and remote documentation URLs.
  • Boundary markers: Includes specific instructions to treat fetched pages and files as untrusted technical data and to ignore any embedded instructions.
  • Capability inventory: Local file system access for dependency inspection and shell execution for standard build and lint tasks.
  • Sanitization: Employs explicit instruction-level boundaries to prevent obedience to untrusted content.
  • [COMMAND_EXECUTION]: The workflow involves running local development commands to verify the haptic implementation.
  • Evidence: Instructions in the 'Verify and report' section suggest running type checks, builds, lints, and tests native to the target repository.
  • [EXTERNAL_DOWNLOADS]: The skill references documentation and source code from the vendor's official domains.
  • Evidence: Links to docs.swmansion.com and github.com/software-mansion are provided for platform-specific technical reference.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 01:41 PM
Security Audit — agent-trust-hub — pulsar-haptics