NYC

asc-app-create-ui

Pass

Audited by Gen Agent Trust Hub on Feb 19, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION] (SAFE): The skill uses a command-line tool named asc to verify and manage App Store records. These operations are core to the skill's functionality.
  • [DATA_EXFILTRATION] (SAFE): The instructions explicitly forbid exporting or storing browser cookies and require a visible browser session, which protects against background data theft.
  • [PROMPT_INJECTION] (LOW): As an automation tool, the skill processes untrusted input such as app names and SKUs. While this presents an indirect prompt injection surface, the risk is mitigated by the 'visible browser session' and 'manual confirmation' requirements. Ingestion points: UI text fields (Name, SKU). Boundary markers: None. Capability inventory: Shell command execution via asc and full browser automation. Sanitization: None mentioned.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 19, 2026, 07:33 PM