rc-forge

Pass

Audited by Gen Agent Trust Hub on Aug 8, 2026

Risk Level: SAFEDATA_EXFILTRATIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill references a sensitive file path ~/.wj_rc_key as a default location for RevenueCat API keys. Accessing files in the user home directory is a form of data exposure, although here it is used for local configuration.- [EXTERNAL_DOWNLOADS]: The skill provides instructions to install a toolkit from the author's repository voys-apps/app-publishing using npx and requires the installation of the pillow library via pip.- [COMMAND_EXECUTION]: The skill relies on executing local Python scripts such as catalog.py and build_paywall.py via the command line to perform API operations and process assets.- [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface by ingesting and processing external media assets and JSON manifests. * Ingestion points: Local asset directories and temporary JSON files. * Boundary markers: None identified. * Capability inventory: Execution of shell commands and Python scripts with file-write and network capabilities. * Sanitization: None; data is read from files and passed directly to API client functions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 8, 2026, 09:57 AM