app-store-aso

Pass

Audited by Gen Agent Trust Hub on May 4, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a local Python script scripts/validate_metadata.py to validate metadata character limits. This script only performs logic-based string length checks and does not possess network or sensitive file access capabilities.
  • [EXTERNAL_DOWNLOADS]: The README and main instructions recommend the installation of krankie, an external CLI tool for tracking keyword rankings, via bun install -g krankie. This tool is provided by the same author and is intended for optional performance monitoring.
  • [PROMPT_INJECTION]: The skill is designed to process user-supplied app metadata. While this represents an indirect prompt injection surface, the skill lacks any high-risk capabilities that could be abused if an injection were present in the processed data.
Audit Metadata
Risk Level
SAFE
Analyzed
May 4, 2026, 07:20 PM
Security Audit — agent-trust-hub — app-store-aso