Expo Brownfield Integration
mweinbach/agent-coworker
Helps add Expo and React Native to an existing native iOS or Android app, and choose between a prebuilt AAR or XCFramework and a fully integrated build.
Performs strict code reviews on React Native plugin projects covering TypeScript, the Kotlin (Android) and Swift (iOS) native bridges, and the Expo config plugin.
$ npx skills add talsec/Free-RASP-ReactNative --skill code-review-react-native -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install talsec/Free-RASP-ReactNative code-review-react-native --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/talsec/Free-RASP-ReactNative.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/code-review-react-native .claude/skills/code-review-react-native && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "code-review-react-native" agent skill from https://github.com/talsec/Free-RASP-ReactNative/tree/master/.agents/skills/code-review-react-native into .claude/skills/code-review-react-native/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review-react-native", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/talsec/Free-RASP-ReactNative/tree/master/.agents/skills/code-review-react-nativeType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add talsec/Free-RASP-ReactNative --skill code-review-react-native -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install talsec/Free-RASP-ReactNative code-review-react-native --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/talsec/Free-RASP-ReactNative.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/code-review-react-native .agents/skills/code-review-react-native && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "code-review-react-native" agent skill from https://github.com/talsec/Free-RASP-ReactNative/tree/master/.agents/skills/code-review-react-native into .agents/skills/code-review-react-native/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review-react-native", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add talsec/Free-RASP-ReactNative --skill code-review-react-native -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install talsec/Free-RASP-ReactNative code-review-react-native --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/talsec/Free-RASP-ReactNative.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/code-review-react-native .cursor/skills/code-review-react-native && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "code-review-react-native" agent skill from https://github.com/talsec/Free-RASP-ReactNative/tree/master/.agents/skills/code-review-react-native into .cursor/skills/code-review-react-native/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review-react-native", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/talsec/Free-RASP-ReactNative.git --path .agents/skills/code-review-react-native--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add talsec/Free-RASP-ReactNative --skill code-review-react-native -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install talsec/Free-RASP-ReactNative code-review-react-native --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/talsec/Free-RASP-ReactNative.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/code-review-react-native .gemini/skills/code-review-react-native && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "code-review-react-native" agent skill from https://github.com/talsec/Free-RASP-ReactNative/tree/master/.agents/skills/code-review-react-native into .gemini/skills/code-review-react-native/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review-react-native", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install talsec/Free-RASP-ReactNative code-review-react-nativeInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add talsec/Free-RASP-ReactNative --skill code-review-react-native -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/talsec/Free-RASP-ReactNative.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/code-review-react-native .github/skills/code-review-react-native && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "code-review-react-native" agent skill from https://github.com/talsec/Free-RASP-ReactNative/tree/master/.agents/skills/code-review-react-native into .github/skills/code-review-react-native/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review-react-native", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add talsec/Free-RASP-ReactNative --skill code-review-react-native -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install talsec/Free-RASP-ReactNative code-review-react-native --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/talsec/Free-RASP-ReactNative.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/code-review-react-native .opencode/skills/code-review-react-native && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "code-review-react-native" agent skill from https://github.com/talsec/Free-RASP-ReactNative/tree/master/.agents/skills/code-review-react-native into .opencode/skills/code-review-react-native/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review-react-native", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
code-review-react-nativePerforms strict code reviews on React Native plugin projects covering TypeScript, the Kotlin (Android) and Swift (iOS) native bridges, and the Expo config plugin.
Code Review React Native is an agent skill from talsec/Free-RASP-ReactNative. Performs strict code reviews on React Native plugin projects covering TypeScript, the Kotlin (Android) and Swift (iOS) native bridges, and the Expo config plugin. Focuses on optimal code, readability, maintainability, deduplication, single-responsibility, straightforward control flow, React Native best practices, the rule that native layers must not invent hardcoded fallbacks for values the TypeScript layer or platform SDK already owns, alignment of identifiers and API surface across TypeScript/Kotlin/Swift…
Its SKILL.md is about 3.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Mobile, covering Cross-platform mobile apps and Code review. It works with React Native, TypeScript, Kotlin and Expo. The repository describes itself as: React Native plugin for Android and iOS mobile devices. SDK providing app protection and threat monitoring. Shield your app with free RASP. Detect reverse engineering, root… The licence is MIT.
12 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 0a0f551. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gityarnghtscnpmFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, yarn, gh and npm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Code Review React Native loads about 3.7k tokens when it runs. Until then it costs about 246 tokens; SKILL.md has 1,720 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from talsec/Free-RASP-ReactNative at commit 0a0f551, republished under its MIT licence (© talsec). 1,720 words, ~3,732 tokens.
.claude/skills/code-review-react-native/SKILL.md (or your agent's skills folder).Strict, opinionated code review for React Native plugin codebases with Kotlin + Swift bridges and an optional Expo config plugin. Optimised for catching the kinds of issues that survive linters and tests but degrade a codebase over time.
const, @deprecated discipline, null vs undefined, strict tsconfig honoured.If the user references a GitHub PR by number:
gh pr view <N> --json title,body,author,state,baseRefName,headRefName,additions,deletions,changedFiles,files,url
gh pr diff <N>
git log <base>..<head> --onelineIf the changes are local:
git diff <base>..HEAD --stat
git diff <base>..HEADAlways read the full file (not only the diff) for any non-trivial change so you see the surrounding context the diff hides — especially around native bridges, event emitter wiring, and EventIdentifiers.
Each file falls into exactly one of these buckets, and the bucket determines what's acceptable:
| Bucket | Examples | Rule |
|---|---|---|
| Hand-written TypeScript | src/ | Full review applies. |
| Built JS output | lib/commonjs/, lib/module/, lib/typescript/ | Must not be hand-edited. Regenerate via yarn build (react-native-builder-bob). |
| Expo config plugin source | plugin/src/ | Full review applies. |
| Expo config plugin build | plugin/build/ | Must not be hand-edited. Regenerate via yarn build or tsc -p plugin/tsconfig.build.json. |
| Hand-written native | android/src/main/kotlin/**, ios/**/*.swift | Full review applies, with extra scrutiny on the bridge layer. |
| Build / config | package.json, *.gradle, *.podspec, tsconfig.json, babel.config.js | Verify version bumps follow SemVer; confirm SDK/binary updates match changelog. |
| Docs / release | CHANGELOG.md, README.md | Verify claims match the diff (e.g. SDK versions, breaking-change list, public-API additions). |
lib/ (built by react-native-builder-bob) and plugin/build/ (compiled from plugin/src/) must be touched only by their build tool.
Red flags:
lib/ that differ from what yarn build would produce.plugin/build/ edited directly instead of editing plugin/src/ and re-running the build.// eslint-disable or // @ts-ignore directive added to a file inside lib/.Action: ask the author to run yarn build and commit the clean output.
A breaking public-API change requires a major version bump. "Public" includes anything exported from src/index.tsx and anything that changes the wire format with the native side.
Common breaks to flag:
If CHANGELOG.md claims SemVer adherence and the bump doesn't match the change, call it out with the affected symbols and the recommended version.
The native layer (Kotlin / Swift) is a transport adapter between TypeScript and the platform SDK. It must not:
optString("foo", "BAR"), as an enum in getOrDefault(Foo.BAR), and again as a fallback object is three sources of truth."SIDELOADED_ONLY"). Use the SDK enum's .name property or avoid manual parsing entirely.Recommended remediation:
NativeModules name must be consistent across all layersThe string used to register and look up the native module must agree across three places:
| Layer | Location | Value |
|---|---|---|
| TypeScript | src/api/nativeModules.ts — NativeModules.FreeraspReactNative | "FreeraspReactNative" |
| Kotlin | FreeraspReactNativeModule.kt companion — const val NAME = "FreeraspReactNative" | "FreeraspReactNative" |
| iOS | RCT_EXPORT_MODULE() / moduleName override in Swift/ObjC bridge | "FreeraspReactNative" |
Any drift in this string causes the module to be undefined at runtime with no compile-time error.
Threats and execution state are delivered through obfuscated event channels. The channel metadata is fetched at runtime from native via two methods:
| Method | Returns | Kotlin | Swift |
|---|---|---|---|
getThreatChannelData | 3 strings: [channelName, threatKey, malwareKey] | getThreatChannelData() promise | getThreatChannelData(_:resolve:reject:) |
getRaspExecutionStateChannelData | 2 strings: [channelName, key] | getRaspExecutionStateChannelData() | getRaspExecutionStateChannelData(_:resolve:reject:) |
Verify for every change touching these methods:
src/channels/threat.ts and src/channels/raspExecutionState.ts destructure by index.src/types/types.ts (TalsecPlugin interface) reflect any change to the array shape.EventIdentifiers must stay obfuscated — never replace with hardcoded stringsios/utils/EventIdentifiers.swift derives all channel identifiers at runtime from RandomGenerator.generateRandomIdentifiers(length: N). This obfuscation is intentional and security-relevant.
Hard blocks:
generatedNumbers[i] reference with a hardcoded string or integer constant.length and updating all index references consistently.The Kotlin side generates its own independent random identifiers via an equivalent mechanism; they are not shared with iOS. This is by design — each process re-generates at launch. Do not attempt to synchronise iOS and Android identifier values.
NativeEventEmitter listener registration and cleanup symmetryEvery addListener(channelName, callback) call on NativeEventEmitter(FreeraspReactNative) must have a matching cleanup path.
Check:
removeListenerForEvent(channelName) is called in Kotlin's removeListenerForEvent react method, and the matching Swift handler does the same.EmitterSubscription (or the subscription stored in useFreeRasp) is .remove()d on cleanup.addListener increments the listener count so the native module doesn't drop events on multi-listener setups.Not every API works on both platforms. Some checks are Android-only (e.g. malware detection, package introspection), some iOS-only (e.g. jailbreak sub-checks).
Required:
/** Android only. No-op on iOS. */TalsecConfig.Red flags:
TalsecConfig-level field read only by one of the two native handlers, with no platform marker.If plugin/src/ changes:
plugin/build/ is regenerated and committed.AndroidManifest.xml, Info.plist, Gradle properties, etc.) and does not duplicate a modification the user's app.json already handles.example/ should demonstrate or at least not break the plugin path.Every newly exported type, enum, or function needs at least:
parse*, build*, and dispatch* methods is three classes.Flag verbatim or near-verbatim repetition, especially:
(0 until arr.length()).map { arr.getString(it) } pattern repeated for every JSON array field in Kotlin. Extract a helper.value ?? defaultValue pattern repeated across multiple config fields. Use a helper or map.runCatching { Enum.valueOf(s) }.getOrDefault(...) calls in Kotlin. Extract a generic parseEnumOr(default) helper.Constructors with 3+ parameters of similar type should be called with named arguments. Positional calls are swap-bug magnets.
When deprecating an API path, ensure the new path doesn't quietly run both code paths. Either short-circuit the deprecated path or document the precedence explicitly.
useFreeRasp hook completenessThe hook is the primary consumer entry point. If new config fields or callbacks are added, verify:
useEffect return) covers any new subscriptions.src/index.tsx.MalwareConfig vs SuspiciousAppDetectionConfig in one PR is one term too many. Pin it before release.@deprecated discipline: deprecating a field is fine; leaving the constructor accepting it with no warning is inconsistent.CHANGELOG.md should be verifiable from git diff <base>..HEAD.npm install is wrong.Structure the review as:
## Summary
<2–3 sentences: what the PR does, overall verdict>
## Blockers / Major issues
### 1. <short title — one line>
<context, citing file:line; show the offending snippet using a code reference>
<concrete remediation>
### 2. ...
## Significant issues
(same shape, less severe)
## Minor / polish
(numbered list, one to three lines each)
## Recommended action
<numbered, ordered list of what must change before merge>Rules for the report:
startLine:endLine:filepath reference form so the user can click through.© talsec, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .agents/skills/code-review-react-native of talsec/Free-RASP-ReactNative.
Open the folder on GitHubat commit 0a0f551
Code Review React Native next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Code Review React Native this skilltalsec/Free-RASP-ReactNative | 175 | — | ~3.7k | Automated safety check: Pass | MIT | |
| Expo Brownfield Integrationmweinbach/agent-coworker | 156 | 2 repos | ~900 | Automated safety check: Notes | Custom licence | |
| Simulator Audio E2Ehyochan/react-native-nitro-sound | 961 | — | ~1.1k | Automated safety check: Pass | MIT | |
| Expo Brownfieldexpo/skills | 2.7k | — | ~1.4k | Automated safety check: Pass | MIT | |
| Clerk Expogeekskai/blog | 103 | — | ~2.8k | Automated safety check: Notes | MIT | |
| Analyticscli TS SDKLeoYeAI/openclaw-master-skills | 2.2k | — | ~5.3k | Automated safety check: Pass | MIT |
mweinbach/agent-coworker
Helps add Expo and React Native to an existing native iOS or Android app, and choose between a prebuilt AAR or XCFramework and a fully integrated build.
hyochan/react-native-nitro-sound
Build and run repeatable react-native-nitro-sound recorder/player regression tests on an iOS Simulator or Android emulator, with explicit virtual-device selection, microphone permission, Maestro…
expo/skills
Integrate Expo and React Native into an existing native iOS or Android app.
geekskai/blog
Add Clerk authentication to Expo and React Native apps using @clerk/expo.
LeoYeAI/openclaw-master-skills
A skill your agent uses when integrating or upgrading the AnalyticsCLI TypeScript SDK in web, TypeScript, React Native, or Expo apps.
CherryHQ/cherry-studio-app
Set up Tailwind CSS v4 in Expo with react-native-css and NativeWind v5 for universal styling
Categories
Performs strict code reviews on React Native plugin projects covering TypeScript, the Kotlin (Android) and Swift (iOS) native bridges, and the Expo config plugin. Code Review React Native is an agent skill from talsec/Free-RASP-ReactNative. Performs strict code reviews on React Native plugin projects covering TypeScript, the Kotlin (Android) and Swift (iOS) native bridges, and the Expo config plugin.
Code Review React Native fits situations like: the user asks to review PR; do a code review; review this code; code review for PRN.
Run `npx skills add talsec/Free-RASP-ReactNative --skill code-review-react-native -a claude-code`. Or copy the skill folder (.agents/skills/code-review-react-native in talsec/Free-RASP-ReactNative) into .claude/skills/code-review-react-native in your project. Claude Code loads it when a task matches its description.
Run `npx skills add talsec/Free-RASP-ReactNative --skill code-review-react-native -a codex`. Or copy the skill folder (.agents/skills/code-review-react-native in talsec/Free-RASP-ReactNative) into .agents/skills/code-review-react-native in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add talsec/Free-RASP-ReactNative --skill code-review-react-native -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-review-react-native, .gemini/skills/code-review-react-native, .github/skills/code-review-react-native and .opencode/skills/code-review-react-native in your project.
Going by SKILL.md and its folder, Code Review React Native needs the command-line tools its instructions call (git, yarn, gh, tsc and npm).
SKILL.md contains no URLs. Its commands use git, gh and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Code Review React Native is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.7k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Code Review React Native: Expo Brownfield Integration (mweinbach/agent-coworker, 156 stars), Simulator Audio E2E (hyochan/react-native-nitro-sound, 961 stars), Expo Brownfield (expo/skills, 2.7k stars) and Clerk Expo (geekskai/blog, 103 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
talsec (a GitHub organization) maintains it in talsec/Free-RASP-ReactNative, which has 175 GitHub stars. The repository was last updated on October 5, 2026.
Source: talsec/Free-RASP-ReactNative on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.