quest-native
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill serves as a legitimate technical guide for VR development on Horizon OS. It directs agents to official documentation hosted by Meta (developers.meta.com) and refers to industry-standard libraries such as the Khronos OpenXR loader. All referenced code samples and build configurations follow standard Android and NDK development practices.
- [INDIRECT_PROMPT_INJECTION]: The skill establishes a data ingestion surface by instructing the agent to search external documentation and analyze local project files.
- Ingestion points: Usage of the
metavrtool for searching Meta's official developer documentation and reading local project files such asAndroidManifest.xmlandbuild.gradle(specified in SKILL.md and references/manifest-and-gradle.md). - Boundary markers: There are no explicit delimiters or specific instructions for the agent to ignore potentially malicious content embedded in documentation search results or local project files.
- Capability inventory: The agent is empowered to provide architectural advice, manifest corrections, and build script modifications based on the ingested data.
- Sanitization: No explicit sanitization or validation logic is defined for data retrieved from external documentation tools or local project files.
Audit Metadata