Back to skill

Security audit

React Native Clean Pattern

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Expo/React Native scaffolding guide, but it gives production app guidance that can store auth tokens insecurely and asks users to run broad unpinned install commands.

Review the install commands before running them, prefer project-local pinned dependencies, and require SecureStore/Keychain/Keystore for authentication secrets. Treat notification token sync, Sentry, Firebase, and auth metadata as privacy-impacting features that need explicit user consent, minimization, and logout or revocation handling.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:18
Finding

Unpinned Global Third-Party Dependency Installation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:145
Finding

Authentication Tokens May Be Persisted in Unencrypted AsyncStorage

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · _agents/workflows/setup-navigation.md (reported line 33)May include surrounding context.

md
### 1. `src/navigation/RootNavigator.tsx` (The Gatekeeper)
Implement the `RootNavigator` stack using the centralized logic:
- **Centralized Options**: Consuming `navigationOptions` from `useAppStyle`.
- **Key-Based Remounting**: Use `key={isAuthenticated ? 'authed' : 'guest'}` on the navigator to clear state during transitions.

## 🟡 Step 4: Implementation (Main Navigator)

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · CHANGELOG.md (reported line 10)May include surrounding context.

md
## [1.0.0] - 2026-04-07

### ✨ Added
- **Clawhub Mobile Skill**: Created standardized `.agents/skills/clawhub-mobile/SKILL.md` for intelligent agent guidance.
- **Master Skill Migration**: Rebranded and cleaned `expo-master.md` to align with Clawhub architecture.
- **ProductDetail Example**: Implemented a reference feature screen demonstrating the mandatory 4-file pattern:
  - `index.tsx` (Pure UI / 4-State Rendering)

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly instructs implementing token persistence for tokens and user metadata but does not require informing the user that sensitive authentication material may be stored on-device. In a provisioning skill that scaffolds production-ready mobile apps, omission of this warning can normalize insecure defaults or lead operators to persist sensitive data without considering retention, encryption, device compromise, or privacy requirements.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill directs implementation of notification token synchronization tied to auth state and message-driven refresh actions, but it omits any warning that device push tokens and related identifiers will be transmitted to backend services and linked to user accounts. This matters because push tokens are device-linked identifiers that can affect privacy, consent, and backend trust boundaries, especially in a production mobile app scaffold intended for reuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill instructs users to install global packages and run setup commands without an explicit warning that these actions modify the host system and may fetch code from external registries. In an agent-skill context, operational commands that change the environment are more sensitive because users may treat the skill as trusted automation guidance and execute commands without reviewing their effects.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.