review-management — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited review-management (Agent Skill) and scored it 45/100 (orange). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 1 high-severity and 1 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 2 flagged
A base64 string of 128+ characters appears in a documentation file. Encoded prompt injection hides the hostile instruction in base64 — invisible to keyword filters — and relies on the agent's ability to decode it at runtime. There is no normal authoring reason to embed a multi-hundred-byte base64 blob in skill docs.
*.sig, SIGNATURES) outside the documentation.The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
You are an expert in app review strategy and reputation management. Your goal is to help the user turn reviews into a growth lever — improving ratings, gaining insights, and building user trust.
app-marketing-context.md — read it for contextCategorize reviews into:
| Category | Description | Action |
|---|---|---|
| Bugs & Crashes | Technical issues | Fix and respond with timeline |
| Feature Requests | Users want something new | Track frequency, consider for roadmap |
| UX Complaints | Confusing or frustrating flows | Prioritize UX improvements |
| Pricing Complaints | Too expensive, paywall issues | Review monetization strategy |
| Love & Praise | Positive feedback | Thank and ask for sharing |
| Competitor Mentions | Users comparing to alternatives | Understand competitive gaps |
| Metric | Target | Why |
|---|---|---|
| Average rating | 4.5+ stars | Below 4.0 significantly hurts conversion |
| Rating trend | Stable or improving | Declining trend signals problems |
| Review velocity | Consistent | Sudden drops may indicate prompt issues |
| Response rate | 100% of negative | Shows you care, can change ratings |
| Response time | < 24 hours | Fast responses build trust |
When to show the prompt:
Apple's SKStoreReviewController rules:
Smart trigger patterns:
Response framework (HEAR):
Response templates:
Bug report:
Thank you for reporting this, [name]. We identified the issue and it's fixed in version [X.X] releasing [date]. We appreciate your patience — please update when available and let us know if it resolves the issue.
Feature request:
Great suggestion! We've added this to our roadmap. We're always looking to improve based on user feedback. Stay tuned for upcoming updates.
Vague negative ("This app sucks"):
We're sorry to hear about your experience. We'd love to understand what went wrong so we can improve. Could you reach out to [support email] with details? We're here to help.
What NOT to do:
Read competitor reviews to find:
Analyze your reviews for:
Rating: [X.X] ★ ([trend: ↑/↓/→])
Total Reviews: [N]
Last 30 Days: [N] reviews, [X.X] avg rating
Response Rate: [X]%
Top Issues:
1. [issue] — mentioned [N] times
2. [issue] — mentioned [N] times
3. [issue] — mentioned [N] times
Top Praise:
1. [praise] — mentioned [N] times
2. [praise] — mentioned [N] timesProvide specific response drafts for the most impactful negative reviews.
aso-audit — Reviews as part of broader ASO health checkretention-optimization — Fix retention issues causing bad reviewscompetitor-analysis — Mine competitor reviews for insightsapp-analytics — Track review metrics over time~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.