software-mobile
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides templates for implementing deep link routers and JavaScript-to-native bridges in WebViews (found in
references/deep-linking-guide.mdandassets/cross-platform/template-webview.md). These components represent ingestion points for untrusted data. The skill mitigates this risk by explicitly instructing developers to validate inputs and sanitize external content before interpolation. - [DYNAMIC_EXECUTION]: A Python script for processing App Store screenshots is provided as a shell-executable heredoc in
references/app-store-connect-checklist.md. This is a standard utility pattern intended for local developer use. - [COMMAND_EXECUTION]: The documentation includes several examples of using development CLI tools such as
adb,xcrun simctl, andcodesignfor testing and verification purposes. These are standard tools within the mobile development ecosystem. - [EXTERNAL_DOWNLOADS]: The skill references established libraries (e.g., Retrofit, OkHttp, SDWebImage, Kingfisher) and well-known services (e.g., Apple, Google, Firebase, Expo). All external references are to reputable industry sources.
Audit Metadata