reversing-react-native-apps

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill describes legitimate reverse engineering workflows for security auditing purposes.\n- [EXTERNAL_DOWNLOADS]: The skill utilizes npx js-beautify to format JavaScript bundles, which fetches the package from the official NPM registry.\n- [COMMAND_EXECUTION]: It employs standard command-line utilities for mobile app analysis, including apktool, apksigner, frida, and objection.\n- [DATA_EXFILTRATION]: Provides instructions to search for sensitive information like API keys and tokens within application bundles as part of a security assessment.\n- [PROMPT_INJECTION]: The skill processes untrusted mobile application files (.apk, .ipa, .bundle).\n
  • Ingestion points: Reads from target.apk and index.android.bundle in SKILL.md.\n
  • Boundary markers: Absent.\n
  • Capability inventory: Includes apktool, apksigner, frida, and hbctool for file manipulation and execution in SKILL.md.\n
  • Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 01:16 AM
Security Audit — agent-trust-hub — reversing-react-native-apps