kotlin-gradle-build
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze external build configuration files (settings.gradle.kts, build.gradle.kts, version catalogs, and CI workflows). This creates an attack surface where malicious instructions embedded in a repository's build files could potentially influence the agent's behavior.
- Ingestion points: Instructions in
SKILL.mddirect the agent to read wrapper properties, settings, root and module builds, version catalogs, and convention plugins. - Boundary markers: The instructions do not specify the use of delimiters or explicit warnings to ignore instructions embedded within the build files.
- Capability inventory: The skill utilizes the shell to execute Gradle commands such as
./gradlew projects,./gradlew check, and./gradlew build. - Sanitization: There is no mention of sanitizing or validating the content of the build files before the agent processes them or executes associated commands.
- [COMMAND_EXECUTION]: The skill explicitly instructs the agent to run shell commands (
./gradlew) to inspect and validate the build state. While these are standard development tasks, they represent the execution of logic defined in the project's build scripts.
Audit Metadata