mobile-design
Pass
Audited by Gen Agent Trust Hub on Feb 20, 2026
Risk Level: SAFE
Full Analysis
- PROMPT_INJECTION (SAFE): The skill uses instructional language to enforce mobile engineering standards and platform-specific rules but does not contain directives to bypass safety filters or override system instructions.\n- DATA_EXFILTRATION (SAFE): No sensitive file access or network communication patterns were detected. The skill explicitly warns against insecure practices like storing tokens in AsyncStorage or logging sensitive data.\n- REMOTE_CODE_EXECUTION (SAFE): No remote code execution patterns, such as piping curl to bash or downloading external scripts, are present.\n- COMMAND_EXECUTION (SAFE): Although the Bash tool is enabled in the metadata, the skill files contain only documentation and code templates, not executable scripts that perform dangerous system operations.\n- OBFUSCATION (SAFE): All content is provided in clear, readable markdown. No hidden characters, encoded strings, or homoglyph-based evasion techniques were found.\n- INDIRECT_PROMPT_INJECTION (LOW): The skill ingests user input for framework and platform choices to calculate an assessment score, but it lacks the capability to execute this input or interpolate it into dangerous contexts.
Audit Metadata