rc-forge
Pass
Audited by Gen Agent Trust Hub on Aug 8, 2026
Risk Level: SAFEDATA_EXFILTRATIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill references a sensitive file path
~/.wj_rc_keyas a default location for RevenueCat API keys. Accessing files in the user home directory is a form of data exposure, although here it is used for local configuration.- [EXTERNAL_DOWNLOADS]: The skill provides instructions to install a toolkit from the author's repositoryvoys-apps/app-publishingusingnpxand requires the installation of thepillowlibrary viapip.- [COMMAND_EXECUTION]: The skill relies on executing local Python scripts such ascatalog.pyandbuild_paywall.pyvia the command line to perform API operations and process assets.- [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface by ingesting and processing external media assets and JSON manifests. * Ingestion points: Local asset directories and temporary JSON files. * Boundary markers: None identified. * Capability inventory: Execution of shell commands and Python scripts with file-write and network capabilities. * Sanitization: None; data is read from files and passed directly to API client functions.
Audit Metadata