{"data":{"skill":{"slug":"wshobson-react-native-architecture","name":"react-native-architecture","icon":"📦","repo":"https://github.com/wshobson/agents/tree/main/plugins/frontend-mobile-development/skills/react-native-architecture","status":"approved","author":"wshobson","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"fc153907-84d8-4571-9c4e-7303b624abf0","skill_id":"138e8611-98aa-47d9-a580-ef65e2959ee1","version":5,"content_hash":"0aea0932e364bf08ac0516667c161ebf","risk_level":"low","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":null,"manual_install_policy":null,"summary":"Static analysis flagged command execution, network links, credential JSON, weak cryptography, and reconnaissance patterns, but review found a Markdown-only React Native guidance skill. The shell commands are documented npx and EAS CLI examples, the URLs are official documentation links, and the credential path is a placeholder with no embedded secret. No prompt injection, hidden execution, credential exfiltration, or malicious intent was found.","remediation":[],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":58,"line_start":51},{"file":"SKILL.md","line_end":647,"line_start":636}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":668,"line_start":668},{"file":"SKILL.md","line_end":669,"line_start":669},{"file":"SKILL.md","line_end":670,"line_start":670},{"file":"SKILL.md","line_end":671,"line_start":671}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[{"title":"User-Run CLI Commands in Documentation","verdict":"FALSE_POSITIVE_LOW_RISK","locations":[{"file":"SKILL.md","line_end":58,"line_start":51},{"file":"SKILL.md","line_end":647,"line_start":636}],"confidence":0.94,"description":"The external command alerts are mostly Markdown fence false positives. The real commands are documented npx and EAS CLI examples that require user action and are normal for React Native setup, but users should review third-party package and build commands before running them.","confidence_reasoning":"The reviewed lines are fenced documentation examples and do not execute automatically. They invoke standard Expo and EAS tooling, so the residual risk is user-run supply-chain exposure rather than malicious skill behavior."},{"title":"External Documentation Links","verdict":"FALSE_POSITIVE","locations":[{"file":"SKILL.md","line_end":668,"line_start":668},{"file":"SKILL.md","line_end":669,"line_start":669},{"file":"SKILL.md","line_end":670,"line_start":670},{"file":"SKILL.md","line_end":671,"line_start":671}],"confidence":0.97,"description":"The hardcoded URL alerts point to Expo, React Native, and FlashList documentation resources. No code sends data to these URLs, and no suspicious tracking or exfiltration endpoint was found.","confidence_reasoning":"The links are visible resource references to reputable project documentation. There is no network execution path or data transfer logic in the skill file."},{"title":"Placeholder Service Account Path","verdict":"FALSE_POSITIVE_LOW_RISK","locations":[{"file":"SKILL.md","line_end":630,"line_start":630}],"confidence":0.91,"description":"The credential JSON alert refers to a sample EAS submit configuration with serviceAccountKeyPath set to ./google-services.json. No credential material is embedded, but production users should keep service account files out of source control.","confidence_reasoning":"The finding is a path string inside an example configuration, not a secret value. It still touches credential handling, so low residual risk remains if users copy the pattern without secret management controls."},{"title":"Weak Cryptography and Reconnaissance Alerts Not Confirmed","verdict":"FALSE_POSITIVE","locations":[{"file":"SKILL.md","line_end":3,"line_start":3},{"file":"SKILL.md","line_end":140,"line_start":140},{"file":"SKILL.md","line_end":444,"line_start":444},{"file":"SKILL.md","line_end":553,"line_start":553},{"file":"SKILL.md","line_end":562,"line_start":562},{"file":"SKILL.md","line_end":639,"line_start":639},{"file":"SKILL.md","line_end":644,"line_start":644},{"file":"SKILL.md","line_end":662,"line_start":662}],"confidence":0.88,"description":"The weak cryptography alert at the description line and reconnaissance alerts in React Native examples are not supported by the surrounding content. The reviewed text contains architecture guidance, navigation parameters, platform checks, and performance examples, not cryptographic code or host reconnaissance.","confidence_reasoning":"Manual review of the cited lines found ordinary prose, typed route parameters, UI callbacks, and EAS commands. No weak cryptographic algorithm or system reconnaissance behavior is present."}],"dangerous_patterns":[],"files_scanned":1,"total_lines":672,"audit_model":"codex","audited_at":"2026-07-01T00:36:31.863+00:00","created_at":"2026-07-01T02:22:10.892035+00:00","static_findings":[],"finding_verdicts":[],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"canonical install advisories are incomplete"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":4,"agentAutoInstallPolicy":null,"manualInstallPolicy":null,"artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}