react-native-skills-vercel

Pass

Audited by Gen Agent Trust Hub on Mar 3, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists primarily of Markdown-based guidelines for React Native and Expo development, including optimizations for list performance, animations, and state management. None of these guidelines contain instructions to bypass AI safety protocols.- [COMMAND_EXECUTION]: The included JavaScript files (main.cjs, pre-execute.cjs, post-execute.cjs) are boilerplate code for the skill's lifecycle and do not perform any sensitive system operations or execute arbitrary commands.- [DATA_EXFILTRATION]: No hardcoded credentials, API keys, or access to sensitive file paths were detected within the 49 files analyzed.- [EXTERNAL_DOWNLOADS]: The skill references well-known and trusted external resources such as the official documentation for React Native, Expo, and Reanimated, as well as reputable community libraries like LegendList and Zeego. No suspicious or unverified remote scripts are downloaded or executed.- [PROMPT_INJECTION]: While the skill defines a surface for ingesting and analyzing target code files (indirect prompt injection surface), it does not include instructions that would lead to the execution of malicious payloads. Ingestion is handled via standard input schemas without bypassing agent constraints.
  • Ingestion points: Target files and paths specified in the skill input.
  • Boundary markers: None explicitly defined in the rule set.
  • Capability inventory: No file-write, network operations, or subprocess executions are performed on the ingested content.
  • Sanitization: Relies on the underlying LLM's standard safety guardrails for processing external content.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 3, 2026, 08:49 AM