dependency-manager

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill instructions define defensive protocols for dependency management, focusing on best practices for Android development such as BOM usage, KSP alignment, and JDK compatibility.
  • [INDIRECT_PROMPT_INJECTION]: The skill operates on external data (dependency files), but implements robust safeguards.
  • Ingestion points: Reads libs.versions.toml and build.gradle.kts files.
  • Boundary markers: Not explicitly defined as markers, but the 'Anti-Hallucination Policy' serves as a logical boundary by requiring external verification for all inputs.
  • Capability inventory: Involves gradle_sync and gradle_build to verify changes.
  • Sanitization: Strictly enforces kebab-case naming and prohibits hardcoded string literals to ensure data consistency.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 08:45 PM
Security Audit — agent-trust-hub — dependency-manager