kotlin-specialist
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests user-provided architectural requirements and model designs to generate implementation code. This creates a standard surface for indirect prompt injection where malicious instructions could theoretically be embedded in the design data.
- Ingestion points: The skill analyzes user-provided architecture, platform targets, and model requirements (SKILL.md, Step 1-2).
- Boundary markers: Absent. The instructions do not specify the use of delimiters (e.g., XML tags) to isolate user-provided technical requirements from the agent's instructions.
- Capability inventory: The skill is primarily focused on code generation and provides templates for implementation and testing. It instructs the agent to run linting tools (detekt, ktlint), which is a common development capability.
- Sanitization: No explicit sanitization or instruction-filtering of the input design data is specified.
- [COMMAND_EXECUTION]: The workflow involves running standard development tools (
detekt,ktlint) for validation. This is a legitimate and expected behavior for a code specialist skill meant to ensure code quality. - [CREDENTIALS_UNSAFE]: The skill correctly handles sensitive information by providing templates that fetch credentials from environment variables (
System.getenv("GITHUB_TOKEN")) or configuration files (environment.config.property("jwt.secret")), which is a security best practice.
Audit Metadata