asc-app-infos
Pass
Audited by Gen Agent Trust Hub on Mar 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
ascCLI tool to interact with App Store Connect, allowing for the management of app info, categories, and localizations through shell-based command execution. - [PROMPT_INJECTION]: The skill contains an indirect prompt injection surface. Ingestion points: Data is ingested from the
.asc/project.jsonfile and the output ofasccommands. Boundary markers: No explicit markers are used to delimit data from instructions. Capability inventory: The skill can execute shell commands and modify app metadata. Sanitization: No sanitization or validation is applied to external data before processing.
Audit Metadata