coverage

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill performs Gradle task execution and Kotlin script automation within the IDE via the 'steroid_execute_code' tool. These actions are required for gathering and displaying coverage data.
  • [PROMPT_INJECTION]: An indirect prompt injection surface is present as the skill ingests data from test failure reports. Ingestion points: Test failure messages and stacktraces from 'build/test-results/*.xml'. Boundary markers: Absent. Capability inventory: Shell command execution and dynamic IDE script execution. Sanitization: Absent.
  • [DATA_EXFILTRATION]: The skill scans project '.properties' files to identify and retrieve code coverage baseline values, which is necessary for its reporting function.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 10:39 AM
Security Audit — agent-trust-hub — coverage