skills/ssheleg/xr-dev/quest-tooling/Gen Agent Trust Hub

quest-tooling

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions for installing the metavr CLI and managed developer tools (such as Perfetto, RenderDoc, and XR Simulator) directly from Meta's official developer portal (developers.meta.com) and GitHub repositories (github.com/meta-quest). These are official channels for the platform's development ecosystem.
  • [REMOTE_CODE_EXECUTION]: Includes the official installation command (curl -fsSL https://developers.meta.com/horizon/install-cli/ | sh) for the metavr CLI. While this pattern executes remote scripts, the source is Meta's verified developer domain.
  • [COMMAND_EXECUTION]: Provides an extensive map of metavr CLI commands for device lifecycle management, build deployment, UI automation, and performance analysis. It also includes diagnostic shell snippets for checking skill installation hygiene and detecting shadowed plugins.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest data from external sources such as Meta documentation, Khronos SDK sources, and CLI outputs. This creates a surface for indirect prompt injection from those external environments. The skill includes mitigation guidance, instructing the agent to verify evidence, use bounded implementation steps, and avoid trusting agent_guidance from source files or sample scripts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 06:45 AM
Security Audit — agent-trust-hub — quest-tooling