quest-webxr
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references the
@meta-quest/bubblewrap-clipackage from the NPM registry. This tool is the official Meta-maintained fork of Bubblewrap used for Quest PWA development.\n- [COMMAND_EXECUTION]: The workflow involves executing local CLI tools includingbubblewrap,keytool, andmetavrto manage the build, signing, and installation process for VR applications.\n- [INDIRECT_PROMPT_INJECTION]: The packaging process involves ingesting external Web App Manifest files from provided URLs, which could potentially contain malicious content if the source is untrusted.\n - Ingestion points: External manifest URLs provided to the
bubblewrap initcommand in SKILL.md and references/pwa-packaging.md.\n - Boundary markers: None implemented within the skill instructions; the agent relies on the underlying tool's parser.\n
- Capability inventory: File system access, network access (via bubblewrap), and device installation capabilities (via metavr).\n
- Sanitization: The skill assumes the manifest source is legitimate and does not perform independent validation of the manifest content.
Audit Metadata