android-compose-components
Pass
Audited by Gen Agent Trust Hub on Aug 9, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill instructions in
SKILL.mdprovide benign guidance for the agent to navigate the documentation files based on user queries. No behavioral overrides or safety bypass attempts were detected. - [DATA_EXFILTRATION]: No hardcoded credentials, sensitive file paths, or unauthorized network operations were found. The code snippets provided are static UI component examples.
- [OBFUSCATION]: The content was analyzed for Base64, zero-width characters, and homoglyphs. No obfuscated code or hidden instructions were found.
- [REMOTE_CODE_EXECUTION]: The skill does not perform any remote script downloads or installations. It references standard Android library dependencies (e.g.,
androidx.compose.material3). - [COMMAND_EXECUTION]: No dangerous system commands, privilege escalation attempts (sudo), or persistence mechanisms were detected.
- [INDIRECT_PROMPT_INJECTION]: The skill acts as a static knowledge base. It does not ingest untrusted data into an execution environment, resulting in a negligible attack surface for indirect injections.
Audit Metadata