coverage
Pass
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill performs Gradle task execution and Kotlin script automation within the IDE via the 'steroid_execute_code' tool. These actions are required for gathering and displaying coverage data.
- [PROMPT_INJECTION]: An indirect prompt injection surface is present as the skill ingests data from test failure reports. Ingestion points: Test failure messages and stacktraces from 'build/test-results/*.xml'. Boundary markers: Absent. Capability inventory: Shell command execution and dynamic IDE script execution. Sanitization: Absent.
- [DATA_EXFILTRATION]: The skill scans project '.properties' files to identify and retrieve code coverage baseline values, which is necessary for its reporting function.
Audit Metadata