barcode-capture-cordova

Pass

Audited by Gen Agent Trust Hub on Apr 29, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is a standard development aid for the Scandit SDK. It follows security best practices by referencing official vendor resources and warns the agent against using potentially outdated training data.\n- [COMMAND_EXECUTION]: The skill documents the use of standard Cordova CLI commands (e.g., cordova plugin add, cordova prepare) necessary to install and sync the Scandit SDK plugins. These are official development tools.\n- [EXTERNAL_DOWNLOADS]: All external URLs point to official Scandit documentation (docs.scandit.com) or their public GitHub samples. These are trusted sources according to the vendor context.\n- [PROMPT_INJECTION]: The skill contains instructions for the agent to proactively fetch documentation and modify user-provided code files. While this creates an ingestion surface for indirect prompt injection, the behavior is constrained to the primary purpose of the skill and does not include any safety bypass patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 29, 2026, 05:51 AM