kotlin-ktor-patterns

Pass

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a documentation resource providing boilerplate code for the Ktor framework. It does not contain executable scripts or commands that would be run on the host system during agent operations.
  • [CREDENTIALS_UNSAFE]: The configuration examples in application.yaml correctly use environment variable placeholders (${JWT_SECRET}, ${DATABASE_URL}) instead of hardcoding sensitive credentials, which aligns with security best practices.
  • [REMOTE_CODE_EXECUTION]: All referenced libraries and dependencies (Netty, Koin, kotlinx.serialization) are well-known, industry-standard components of the Kotlin/JVM ecosystem.
  • [DATA_EXFILTRATION]: CORS configuration in configureCORS() demonstrates safe practices by restricting allowed hosts to localhost:3000 and example.com rather than using wildcards.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 13, 2026, 08:44 PM
Security Audit — agent-trust-hub — kotlin-ktor-patterns