{"data":{"skill":{"slug":"babakbar-react-native-mobile-development","name":"React Native Mobile Development","icon":"📦","repo":"https://github.com/BabakBar/VibeKeeper/tree/main/.claude/skills/react-native-mobile","status":"approved","author":"BabakBar","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"c6696ee0-9fd0-424c-bff9-775215d91ca7","skill_id":"25dc175f-2cbd-4ecb-bc48-ae75469bbaf0","version":6,"content_hash":"cf3148b0b504b2dfd5967c692e5c5eea","risk_level":"medium","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":null,"manual_install_policy":null,"summary":"Static analysis flagged external command examples, documentation URLs, and several blocker patterns. Review found no prompt injection, malicious intent, credential access, or data exfiltration; the weak cryptography and system reconnaissance matches are false positives. The remaining risk is that the skill permits Bash and file edits while recommending npm, npx, Expo, iOS, and Android commands that can execute project scripts or install third-party packages.","remediation":[],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":31,"line_start":24},{"file":"SKILL.md","line_end":138,"line_start":137}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":145,"line_start":144}]},{"factor":"filesystem","evidence":[{"file":"SKILL.md","line_end":4,"line_start":4}]}],"critical_findings":[],"high_findings":[],"medium_findings":[{"title":"External Development Commands Require Review","locations":[{"file":"SKILL.md","line_end":31,"line_start":24},{"file":"SKILL.md","line_end":138,"line_start":137}],"confidence":0.72,"description":"The skill recommends npm, npx, Expo, iOS, and Android commands. This is appropriate for React Native work, but these commands can run package scripts, install dependencies, or modify native project files when executed by an agent.","confidence_reasoning":"The command guidance is explicit and relevant to the skill purpose. Risk depends on the target project and package sources, so this is a legitimate operational risk rather than confirmed malicious behavior."},{"title":"Broad Agent Tool Permissions","locations":[{"file":"SKILL.md","line_end":4,"line_start":4}],"confidence":0.68,"description":"The skill declares Bash, Read, Write, Edit, Grep, and Glob permissions. These tools are useful for mobile development, but they allow command execution and filesystem changes if the host agent grants them.","confidence_reasoning":"The permissions are directly declared in the skill header. They are common for coding workflows, but users should understand the impact before using the skill on sensitive repositories."}],"low_findings":[{"title":"Documentation URLs Are Benign Network References","locations":[{"file":"SKILL.md","line_end":145,"line_start":144}],"confidence":0.91,"description":"The hardcoded URLs point to React Native and Expo documentation. They do not include tracking parameters, credential collection, or instructions to send project data to an external endpoint.","confidence_reasoning":"The URLs are visible documentation links to expected official resources for this topic. No evidence found of network exfiltration or hidden download behavior."},{"title":"Static Blocker Matches Are False Positives","locations":[{"file":"SKILL.md","line_end":3,"line_start":3},{"file":"SKILL.md","line_end":26,"line_start":26},{"file":"SKILL.md","line_end":96,"line_start":96}],"confidence":0.94,"description":"The weak cryptography match on the description line and system reconnaissance matches are not supported by the file content. The referenced lines describe mobile app development, running Android, and React Native styling guidance.","confidence_reasoning":"Manual review of the exact lines found no cryptographic algorithm use and no host reconnaissance command. The static signals appear to be keyword or markdown-context mistakes."},{"title":"Markdown Code Fences Triggered Command Pattern Matches","locations":[{"file":"SKILL.md","line_end":65,"line_start":36},{"file":"SKILL.md","line_end":92,"line_start":69},{"file":"SKILL.md","line_end":126,"line_start":105},{"file":"SKILL.md","line_end":133,"line_start":128}],"confidence":0.9,"description":"Several Ruby or shell backtick detections correspond to fenced TypeScript examples and inline Markdown formatting. These examples are instructional React Native snippets, not executable shell code.","confidence_reasoning":"The matched sections are Markdown fenced code blocks containing React Native component examples. They do not invoke a shell or process untrusted input."}],"dangerous_patterns":[{"title":"npm and npx Command Guidance","locations":[{"file":"SKILL.md","line_end":31,"line_start":24},{"file":"SKILL.md","line_end":138,"line_start":137}],"confidence":0.74,"description":"The skill instructs agents to use npm and npx commands for Metro, Expo, iOS, Android, prebuild, and cache clearing workflows. These commands can execute local package scripts and dependency install hooks.","confidence_reasoning":"The commands are present and executable in normal project contexts. They are not malicious by themselves, but they carry known supply-chain and local-script execution risk."}],"files_scanned":1,"total_lines":146,"audit_model":"codex","audited_at":"2026-06-28T13:09:40.28+00:00","created_at":"2026-06-28T14:22:55.929525+00:00","static_findings":[],"finding_verdicts":[],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"canonical install advisories are incomplete"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"low","confirmedFindingCount":1,"capabilityReviewCount":2,"needsReviewCount":0,"falsePositiveCount":2,"agentAutoInstallPolicy":null,"manualInstallPolicy":null,"artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}