kotlin-ktor-patterns
Pass
Audited by Gen Agent Trust Hub on Jul 13, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as a documentation resource providing boilerplate code for the Ktor framework. It does not contain executable scripts or commands that would be run on the host system during agent operations.
- [CREDENTIALS_UNSAFE]: The configuration examples in
application.yamlcorrectly use environment variable placeholders (${JWT_SECRET},${DATABASE_URL}) instead of hardcoding sensitive credentials, which aligns with security best practices. - [REMOTE_CODE_EXECUTION]: All referenced libraries and dependencies (Netty, Koin, kotlinx.serialization) are well-known, industry-standard components of the Kotlin/JVM ecosystem.
- [DATA_EXFILTRATION]: CORS configuration in
configureCORS()demonstrates safe practices by restricting allowed hosts tolocalhost:3000andexample.comrather than using wildcards.
Audit Metadata