skills/expo/skills/expo-app-clip/Gen Agent Trust Hub

expo-app-clip

Pass

Audited by Gen Agent Trust Hub on Aug 4, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses bunx, npx, and eas to execute various development tools, including setup-safari and testflight. It also uses shell commands like mkdir and touch to set up directory structures for the Apple App Site Association (AASA) files.
  • [REMOTE_CODE_EXECUTION]: Includes a feedback mechanism that runs npx --yes submit-expo-feedback@latest. This pattern downloads and executes the latest version of a script from the npm registry. Within the context of this vendor-authored skill, this is used as a standard support and feedback channel.
  • [EXTERNAL_DOWNLOADS]: References and fetches resources from expo.dev, expo.app, and github.com. It also directs users to technical documentation hosted on sosumi.ai, which is a common resource for Apple-related technical specifications in the Expo ecosystem.
  • [DATA_EXFILTRATION]: Contains a feedback loop that transmits user-provided or agent-generated feedback to the vendor's ingestion service. This is a functional requirement for the skill's maintenance and is restricted to the specified feedback CLI.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 4, 2026, 11:04 PM
Security Audit — agent-trust-hub — expo-app-clip