skills/keychat-io/keychat-app/run/Gen Agent Trust Hub

run

Pass

Audited by Gen Agent Trust Hub on Feb 28, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill employs official development tools (Flutter) to manage application execution on devices or simulators. Its functionality is limited to standard build and run tasks consistent with its stated purpose.
  • [PROMPT_INJECTION]: The skill was evaluated for indirect prompt injection risks due to the use of user-provided arguments. 1. Ingestion points: User-supplied device IDs are accepted via the $ARGUMENTS parameter. 2. Boundary markers: No explicit markers are defined in the workflow documentation. 3. Capability inventory: Command execution is restricted to the Bash tool with a specific flutter * filter. 4. Sanitization: No explicit input sanitization is performed in the workflow; however, the risk is mitigated by the restrictive nature of the allowed command set.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 28, 2026, 06:45 PM