software-mobile

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides templates for implementing deep link routers and JavaScript-to-native bridges in WebViews (found in references/deep-linking-guide.md and assets/cross-platform/template-webview.md). These components represent ingestion points for untrusted data. The skill mitigates this risk by explicitly instructing developers to validate inputs and sanitize external content before interpolation.
  • [DYNAMIC_EXECUTION]: A Python script for processing App Store screenshots is provided as a shell-executable heredoc in references/app-store-connect-checklist.md. This is a standard utility pattern intended for local developer use.
  • [COMMAND_EXECUTION]: The documentation includes several examples of using development CLI tools such as adb, xcrun simctl, and codesign for testing and verification purposes. These are standard tools within the mobile development ecosystem.
  • [EXTERNAL_DOWNLOADS]: The skill references established libraries (e.g., Retrofit, OkHttp, SDWebImage, Kingfisher) and well-known services (e.g., Apple, Google, Firebase, Expo). All external references are to reputable industry sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:07 PM
Security Audit — agent-trust-hub — software-mobile