optimising-expo-react-native-performance
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's primary function involves the agent ingesting and analyzing untrusted content from a target repository, which represents an attack surface for instructions embedded in data.
- Ingestion points: The agent processes repository files including
package.json,app.json,metro.config.js,babel.config.*,eas.json, and user-provided problem reports as specified inSKILL.md. - Boundary markers: There are no instructions for the agent to utilize specific delimiters or to ignore embedded natural language instructions within the ingested data files.
- Capability inventory: The agent is authorized to execute development CLI tools (
npx expo,eas cli), modify source code, and perform file system operations. - Sanitization: The workflow does not include steps for validating or sanitizing external content before it is used to drive the agent's logic.
- [COMMAND_EXECUTION]: The skill requires the agent to execute various CLI commands and platform-specific profiling tools.
- Evidence: Instructions in
SKILL.mdandreferences/06-ci-regression.mdinvolve runningnpx expo export,eas build, and custom Node.js scripts for size reporting. - Context: While these are standard developer operations for performance auditing, they constitute active command execution capabilities driven by the skill's instructions.
Audit Metadata