quest-tooling
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides instructions for installing the
metavrCLI and managed developer tools (such as Perfetto, RenderDoc, and XR Simulator) directly from Meta's official developer portal (developers.meta.com) and GitHub repositories (github.com/meta-quest). These are official channels for the platform's development ecosystem. - [REMOTE_CODE_EXECUTION]: Includes the official installation command (
curl -fsSL https://developers.meta.com/horizon/install-cli/ | sh) for themetavrCLI. While this pattern executes remote scripts, the source is Meta's verified developer domain. - [COMMAND_EXECUTION]: Provides an extensive map of
metavrCLI commands for device lifecycle management, build deployment, UI automation, and performance analysis. It also includes diagnostic shell snippets for checking skill installation hygiene and detecting shadowed plugins. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest data from external sources such as Meta documentation, Khronos SDK sources, and CLI outputs. This creates a surface for indirect prompt injection from those external environments. The skill includes mitigation guidance, instructing the agent to verify evidence, use bounded implementation steps, and avoid trusting
agent_guidancefrom source files or sample scripts.
Audit Metadata