skills/ssheleg/xr-dev/quest-webxr/Gen Agent Trust Hub

quest-webxr

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references the @meta-quest/bubblewrap-cli package from the NPM registry. This tool is the official Meta-maintained fork of Bubblewrap used for Quest PWA development.\n- [COMMAND_EXECUTION]: The workflow involves executing local CLI tools including bubblewrap, keytool, and metavr to manage the build, signing, and installation process for VR applications.\n- [INDIRECT_PROMPT_INJECTION]: The packaging process involves ingesting external Web App Manifest files from provided URLs, which could potentially contain malicious content if the source is untrusted.\n
  • Ingestion points: External manifest URLs provided to the bubblewrap init command in SKILL.md and references/pwa-packaging.md.\n
  • Boundary markers: None implemented within the skill instructions; the agent relies on the underlying tool's parser.\n
  • Capability inventory: File system access, network access (via bubblewrap), and device installation capabilities (via metavr).\n
  • Sanitization: The skill assumes the manifest source is legitimate and does not perform independent validation of the manifest content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 06:45 AM
Security Audit — agent-trust-hub — quest-webxr