store-compliance

Pass

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill instructs the agent to 'Do NOT ask the user questions,' which suppresses user oversight and bypasses standard interaction patterns.
  • [PROMPT_INJECTION]: The skill has a surface for indirect prompt injection as it processes untrusted app metadata from files like AndroidManifest.xml and Info.plist. Malicious instructions embedded in app descriptions or names could influence the agent's behavior during the audit. • Ingestion points: AndroidManifest.xml, Info.plist, fastlane/metadata/. • Boundary markers: Absent. • Capability inventory: File read access and local telemetry logging. • Sanitization: Absent.
  • [COMMAND_EXECUTION]: The 'SELF-EVOLUTION TELEMETRY' section directs the agent to perform file system checks and write operations to the ~/.claude/projects/ directory. While intended for logging within the Claude Code framework, this involves writing to paths outside the immediate project workspace.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 23, 2026, 10:57 AM
Security Audit — agent-trust-hub — store-compliance