kotlin-specialist

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests user-provided architectural requirements and model designs to generate implementation code. This creates a standard surface for indirect prompt injection where malicious instructions could theoretically be embedded in the design data.
  • Ingestion points: The skill analyzes user-provided architecture, platform targets, and model requirements (SKILL.md, Step 1-2).
  • Boundary markers: Absent. The instructions do not specify the use of delimiters (e.g., XML tags) to isolate user-provided technical requirements from the agent's instructions.
  • Capability inventory: The skill is primarily focused on code generation and provides templates for implementation and testing. It instructs the agent to run linting tools (detekt, ktlint), which is a common development capability.
  • Sanitization: No explicit sanitization or instruction-filtering of the input design data is specified.
  • [COMMAND_EXECUTION]: The workflow involves running standard development tools (detekt, ktlint) for validation. This is a legitimate and expected behavior for a code specialist skill meant to ensure code quality.
  • [CREDENTIALS_UNSAFE]: The skill correctly handles sensitive information by providing templates that fetch credentials from environment variables (System.getenv("GITHUB_TOKEN")) or configuration files (environment.config.property("jwt.secret")), which is a security best practice.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 09:19 PM
Security Audit — agent-trust-hub — kotlin-specialist