mobile-sdk-upgrade

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill uses standard mobile development commands (npx expo, flutter upgrade, npm install) to facilitate SDK migrations. These operations are performed within the local project context using official tools.
  • [SAFE]: All external links point to official documentation and well-known platforms (docs.expo.dev, expo.dev, npmjs.com, docs.flutter.dev, dart.dev).
  • [SAFE]: The skill implements best practices for safety, including automatic creation of Git snapshots before destructive changes and clear rollback strategies in case of failure.
  • [INDIRECT_PROMPT_INJECTION]: While the skill ingests local project data (dependency lists and build logs) to perform audits, it does so using structured MCP tools and standard CLI output analysis. The risk of indirect prompt injection is minimal given the technical nature of the ingested data and the use of specialized developer tools for processing.
  • [SAFE]: No obfuscation, data exfiltration, or persistence mechanisms were detected. The command execution is restricted to standard package management and build lifecycle tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 07:49 AM
Security Audit — agent-trust-hub — mobile-sdk-upgrade